Dashboards & Visualizations

Does anybody know of an example app demonstrating event-renderers.conf in action?

muebel
SplunkTrust
SplunkTrust

I don't see it in Nick's UI example app, but it looks like a powerful utility and I can't get it to work. What would be an example of the configuration needed to do something simple such as change the font size of an event in a table if it matched an event type?

This is sort of a continuation of http://answers.splunk.com/questions/7378/modifying-css-to-colorize-table-rows-in-dashboard-panel-wit... in general, but more pointed at successful use of event-renders.conf.

Tags (3)

sideview
SplunkTrust
SplunkTrust

The discover app also uses a neat custom event renderer, actually for its navigation on the homepage.

There's a csv file in the app whose rows represent the views in the app, and I rendered the results in an EventsViewer on the app's homepage, using an event renderer and some custom behaviour in application.js to wire it all up.

I've thought about really taking that technique to the next level and doing away with the AppBar entirely -- just making dynamic navigation modules to render views and searches in categories.

Anyway, mileage may vary. hth.

Dan
Splunk Employee
Splunk Employee

Actually, the default search app has custom event renderers for the experimental features crawl and discover-eventtypes.

You can see the discover-eventtype renderer in action if you pipe a search to the | findtypes command.

$SPLUNK_HOME/etc/apps/search/default/event_renderers.conf:

[discovered_eventtype_stanza]
eventtype = discovered_eventtype
template = discovered.html
priority = 200

[crawled_files_stanza]
eventtype = crawled_files
template = crawledfile.html
priority = 200

The event renderers themselves are in $SPLUNK_HOME/etc/apps/search/appserver/event_renderers/

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...