[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2r46uevo6oqv":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6abacf18ca21c797c7e9a51b","put-splunk-search-results-in-your-own-apps-data-grid-214b3d62","Put Splunk Search Results in Your Own App's Data Grid","Products that run on infrastructure have a strong chance of having their events in Splunk.","news",[10,13,18,23,28,33,38,43,48,53],{"headline":6,"body":11,"imageUrl":12,"sourceImageUrl":12},"Products that run on infrastructure have a strong chance of having their events in Splunk. The people who need to see those events are often in your application, not in Splunk, and often without a Splunk seat. The usual answers are an iframe around a Splunk dashboard, or a hand-built table over the REST API that re-implements filtering and paging badly.","https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1b1izkeazld0h1hfdzsi.png",{"headline":14,"body":15,"imageUrl":16,"images":17},"Lattice Grid has a Splunk adapter that does","Lattice Grid has a Splunk adapter that does the translation for you. This post shows what it does, what it deliberately does not do, and the three ways to handle the credential depending on who the page is for.","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"Splunk's on-disk index format is closed. There is","Splunk's on-disk index format is closed. There is no file to read and no bucket to open. The supported surface is the search REST API, so that is what the adapter speaks: it dispatches a search job, watches it, reads a window of results, and cancels the job the moment the grid asks for something else.","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"Give it a base search and the grid","Give it a base search and the grid is live over it. Typing into the filter row, clicking a column header to sort, or scrolling to the next page each becomes a Splunk search job. The browser only ever receives the rows in view.","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"SPL has two ways to say \"keep the","SPL has two ways to say \"keep the events where this holds\". | where is an eval expression: exact, case-sensitive, applied after the events have been read. The search command's own terms are matched against the index, case-insensitively, with wildcards. The adapter emits the search form, for two reasons. It is the faster one, because Splunk seeks rather than reads and discards. And it is the one whose result matches what the same filter means everywhere else in the grid, whose filter kernel compares strings case-insensitively unless a condition asks otherwise.","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"That choice has a cost, and the adapter","That choice has a cost, and the adapter names it rather than hiding it. A condition that asks for caseSensitive cannot be honoured by a case-insensitive matcher, so it is pushed case-insensitively and the grid says so once in the console. Returning quietly wider rows is the failure this adapter exists not to have.","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"Values never leave their quotes. Strings are wrapped","Values never leave their quotes. Strings are wrapped and escaped, including the asterisk, because an unescaped * inside a quoted SPL value is a wildcard. A user who types foo*bar into a filter box gets events containing foo*bar, not everything from foo to bar. The wildcards that contains, startsWith and endsWith need are added outside the escaped text, so the adapter's wildcards are wildcards and the user's are literal. Field names are validated against a pattern and refused by name otherwise, since the identifier is the one part of an SPL expression that cannot be quoted away. Time filters become the job's window","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"Splunk's earliest_time is inclusive and latest_time is exclusive","Splunk's earliest_time is inclusive and latest_time is exclusive. So a >= on the time column maps onto earliest_time exactly and a \u003C maps onto latest_time exactly. The adapter lifts those two out of the filter expression and makes them the job's own window, which is the difference between Splunk seeking to a time range and Splunk reading everything and discarding most of it.","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"The bounds that do not map exactly, >","The bounds that do not map exactly, > and \u003C=, and any time condition inside an or, stay in the expression as a numeric comparison on the time field. That is exact, just not as fast. Correct first, fast where correctness allows. After each query the source reports what ran in Splunk and what, if anything, stayed in the browser:","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"For most filter shapes the answer is \"pushed","For most filter shapes the answer is \"pushed all\". When it is not, the plan tells you which condition was finished client-side and why, so there is never a silent gap between the filter the user set and the rows they see. Where the credential lives","\u002Fapi\u002Fmedia\u002Fposts\u002Fput-splunk-search-results-in-your-own-apps-data-grid-214b3d62\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Dev.to","https:\u002F\u002Fdev.to\u002Ftonygoodchild\u002Fput-splunk-search-results-in-your-own-apps-data-grid-5fn7","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},3,0,"2026-09-28T20:33:28.288Z","local"]