{
  "id": 10519784,
  "title": "Put Splunk Search Results in Your Own App's Data Grid",
  "url": "https://urgent.news/2026/09/28/put-splunk-search-results-in-your-own-apps-data-grid",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T19:53:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/tonygoodchild/put-splunk-search-results-in-your-own-apps-data-grid-5fn7"
  },
  "original_language": "en",
  "account": "Splunk search results can be displayed in your custom application using the Lattice Grid framework. This solution is beneficial for users who need to view events in your application, not Splunk, and may not have a Splunk license. The Lattice Grid provides a Splunk adapter that handles the translation between your application's grid and Splunk's search REST API.\n\nThe adapter performs a search job, watches it, reads a window of results, and cancels the job when the grid requests a different set of data. The adapter supports three methods for handling credentials based on the page's intended audience.\n\nIn production environments, a proxy server is recommended. The application authenticates visitors, and a small backend holds the Splunk service token. The proxy forwards only the necessary search endpoints, restricts index permissions, implements rate-limiting, and adds cross-origin headers. Your custom application interacts with this proxy, never directly accessing the Splunk token.\n\nFor internal tools, a per-user session key can be used. Each user signs into Splunk using their own account, and the page stores their short-lived session key in memory. The adapter fetches the session key from Splunk during login and uses it to make subsequent requests.\n\nThe adapter ensures that users see only the rows within the specified time window. It converts time filters into the job's window, making Splunk seek to the time range instead of reading the entire dataset and discarding most of it. This approach allows for faster filtering and avoids silent gaps between the user's filter and the rows displayed.",
  "summary": "Products that run on infrastructure have a strong chance of having their events in Splunk. The people who need to see those events are often in your application, not in Splunk, and often without a Splunk seat. The usual answers are an iframe around a Splunk dashboard, or a hand-built table over the REST API that re-implements filtering and paging badly. Lattice Grid has a Splunk adapter that does…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}