Dashboards & Visualizations

Display received html file on dashboard

eholz1
Contributor

Hello Splunkers!

I am using HEC to send an html file to splunk. The received event contains the html lines of code.

The html is a table with some data, and forms a table with the data. Is there a way, or how can I create a dashboard from the html text that shows the table? 

Maybe another way to say this is: How can I extract the html code from the hec event, and display same on a dashboard?

 

Thank You So Much,

E Holz

 

Labels (1)
Tags (1)
0 Karma
1 Solution

livehybrid
Ultra Champion

Hi @eholz1 

This is possible with some custom JS with a classic dashboard, but not yet possible with Dashboard Studio.

Rather then me pasting the whole process here, check out https://community.splunk.com/t5/Dashboards-Visualizations/Render-HTML-code-from-search-result-in-Spl... which gives an example of how to achieve this.

:glowing_star: Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
Ultra Champion

Hi @eholz1 

This is possible with some custom JS with a classic dashboard, but not yet possible with Dashboard Studio.

Rather then me pasting the whole process here, check out https://community.splunk.com/t5/Dashboards-Visualizations/Render-HTML-code-from-search-result-in-Spl... which gives an example of how to achieve this.

:glowing_star: Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

eholz1
Contributor

Hello There  Ultra Champ,

 

Thanks for quick response. I will take a look at the process. Thanks again,

@eholz1

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Be aware though that allowing displaying an unescaped, unsanitized HTML code from potentially unknown source is not always a best idea.

eholz1
Contributor

Hello PickleRick,

 

I now know what you mean, the demo link using "| makeresults" fails. Lucky for me the html I use seems OK,

and I do get the display of the table and the data iin the html code/file, thanks for the TIP. 

@eholz1

Tags (1)
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...