All Apps and Add-ons

Change the splunk xml view for windows events

Vishnukv65
New Member

Hi Team,

 

When i search splunk for windows events i am getting the result in xml format. Is there any way we can change the view from xml format to any easily readable format?

Labels (1)
0 Karma

Vishnukv65
New Member

Hi ITwhisperer, Thanks for the reply. My requirement is when i simply query splunk for the event details the event descriptions are showing in xml format. So its really difficult for me to exactly see. Previously i can see the event description/details in normal html format. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can extract fields from the xml using various techniques and display them in a table or chart depending on your requirements. What information are you interested in from your XML events?

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...