All Apps and Add-ons

Change the splunk xml view for windows events

Vishnukv65
New Member

Hi Team,

 

When i search splunk for windows events i am getting the result in xml format. Is there any way we can change the view from xml format to any easily readable format?

Labels (1)
0 Karma

Vishnukv65
New Member

Hi ITwhisperer, Thanks for the reply. My requirement is when i simply query splunk for the event details the event descriptions are showing in xml format. So its really difficult for me to exactly see. Previously i can see the event description/details in normal html format. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can extract fields from the xml using various techniques and display them in a table or chart depending on your requirements. What information are you interested in from your XML events?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...