Getting Data In

What is the best way to display a payload with line breaks for better readability in Splunk Web?

ram_85
Explorer

I want to display the payload with line breaks for better readability on Splunk Web.

Splunk receives the payload as a stream of data with no line breaks which results in a continuous text. So we included a unique string at the end of the line before sending to Splunk. We are trying to replace the unique string 
     with line breaks so that it will helps the with the readability. Will LINE_BREAKER work for this?

Current:


    Exception in thread "main" java.lang.NullPointerException
    at com.example.myproject.Book.getTitle(Book.java:16)
    at com.example.myproject.Author.getBookTitles(Author.java:25)
    at com.example.myproject.Bootstrap.main(Bootstrap.java:14)
    
    

Expected:

Exception in thread "main" java.lang.NullPointerException
at com.example.myproject.Book.getTitle(Book.java:16)
at com.example.myproject.Author.getBookTitles(Author.java:25)
at com.example.myproject.Bootstrap.main(Bootstrap.java:14)
0 Karma
1 Solution

ram_85
Explorer

This works for me.

| rex mode=sed "s/ /\n/g"

View solution in original post

0 Karma

ram_85
Explorer

This works for me.

| rex mode=sed "s/ /\n/g"

0 Karma

ram_85
Explorer

Rex mode command works and I am assuming SEDCMD will also work. I am worried about the performance. Will there be any impacts on the performance if SEDCMD command is used?

rex mode=sed "s/ /\n/g"
SEDCMD-breaklinekpaths=s/ /\n/g

0 Karma

bmacias84
Champion

Should be too bad, but this seem to be your only option.

0 Karma

bmacias84
Champion

LINE_BREAKER is intended to create new events which I doubt you want each line to be a separate Splunk event. Why is your log inserting characters as HTML entities? I think the best way would be to use sed to convert all the html entities or build a Splunk command.

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...