Splunk Search

Does anyone already have a Formatter (User defined language) for Splunk search text or dashboard XMLs on Eclipse or Notepad++?

koprai
Explorer

Searched a bit, but could find anything. Does anyone already have a Formatter for Splunk search text or Splunk dashboard XMLs (that include prettying the embedded search elements). Ideal if it is pluggable with Notepad++ or Eclipse.

Even though I write the searchTemplate and searchPostProcesses with proper indentation and line breaks on the dashboard XML, when I explore the search via the panel, the search indentations get lost. Indentations also get lost if dashboard.xml gets overwritten as a result of panel edits. Without indentation and formatting, it is very difficult to understand complicated queries.

A formatter that does indentation and line-breaks based on “|” and “[“ and “]” would be great. I know it is possible to define User Defined Language formatter in notepad++ and Eclipse. I wanted to know if someone already has it or if there is a Splunk Formatted App.. IMO native search text formatting should be a feature request for Splunk (both in dashboard XMLs and in search box)

mew1033
Explorer

I found one here: http://www.bbosearch.com/pretty
I'd really like to turn it into a sublime plugin or something...

0 Karma

MuS
Legend

not an real answer to your question but nice anyways https://github.com/yorokobi/vim-splunk

Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...