Dashboards & Visualizations

Does anybody know of an example app demonstrating event-renderers.conf in action?

muebel
SplunkTrust
SplunkTrust

I don't see it in Nick's UI example app, but it looks like a powerful utility and I can't get it to work. What would be an example of the configuration needed to do something simple such as change the font size of an event in a table if it matched an event type?

This is sort of a continuation of http://answers.splunk.com/questions/7378/modifying-css-to-colorize-table-rows-in-dashboard-panel-wit... in general, but more pointed at successful use of event-renders.conf.

Tags (3)

sideview
SplunkTrust
SplunkTrust

The discover app also uses a neat custom event renderer, actually for its navigation on the homepage.

There's a csv file in the app whose rows represent the views in the app, and I rendered the results in an EventsViewer on the app's homepage, using an event renderer and some custom behaviour in application.js to wire it all up.

I've thought about really taking that technique to the next level and doing away with the AppBar entirely -- just making dynamic navigation modules to render views and searches in categories.

Anyway, mileage may vary. hth.

Dan
Splunk Employee
Splunk Employee

Actually, the default search app has custom event renderers for the experimental features crawl and discover-eventtypes.

You can see the discover-eventtype renderer in action if you pipe a search to the | findtypes command.

$SPLUNK_HOME/etc/apps/search/default/event_renderers.conf:

[discovered_eventtype_stanza]
eventtype = discovered_eventtype
template = discovered.html
priority = 200

[crawled_files_stanza]
eventtype = crawled_files
template = crawledfile.html
priority = 200

The event renderers themselves are in $SPLUNK_HOME/etc/apps/search/appserver/event_renderers/

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...