Dashboards & Visualizations

Does anybody know of an example app demonstrating event-renderers.conf in action?

muebel
SplunkTrust
SplunkTrust

I don't see it in Nick's UI example app, but it looks like a powerful utility and I can't get it to work. What would be an example of the configuration needed to do something simple such as change the font size of an event in a table if it matched an event type?

This is sort of a continuation of http://answers.splunk.com/questions/7378/modifying-css-to-colorize-table-rows-in-dashboard-panel-wit... in general, but more pointed at successful use of event-renders.conf.

Tags (3)

sideview
SplunkTrust
SplunkTrust

The discover app also uses a neat custom event renderer, actually for its navigation on the homepage.

There's a csv file in the app whose rows represent the views in the app, and I rendered the results in an EventsViewer on the app's homepage, using an event renderer and some custom behaviour in application.js to wire it all up.

I've thought about really taking that technique to the next level and doing away with the AppBar entirely -- just making dynamic navigation modules to render views and searches in categories.

Anyway, mileage may vary. hth.

Dan
Splunk Employee
Splunk Employee

Actually, the default search app has custom event renderers for the experimental features crawl and discover-eventtypes.

You can see the discover-eventtype renderer in action if you pipe a search to the | findtypes command.

$SPLUNK_HOME/etc/apps/search/default/event_renderers.conf:

[discovered_eventtype_stanza]
eventtype = discovered_eventtype
template = discovered.html
priority = 200

[crawled_files_stanza]
eventtype = crawled_files
template = crawledfile.html
priority = 200

The event renderers themselves are in $SPLUNK_HOME/etc/apps/search/appserver/event_renderers/

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...