2 items
Macro and lookup hover popups, a lookup clause builder with live sample preview, and copy-to-clipboard icons across Splunk Web. Hover Actions for SPL adds quality-of-life tooling to Splunk Web for people who live in the search bar. HOVER POPUPS IN THE SEARCH BAR - Hover a `macro` to see its full definition inline, with a one-click jump to the definition page — no more digging through Settings to remember what a macro expands to. - Hover a lookup file or lookup definition to see the owning app, its backing source (CSV file or KV store collection), its fields, and a sample row. - Deep links to edit the lookup in the Lookup File Editor app or open the definition in Settings. - Same-named objects in multiple apps? All matches are listed with their app so you pick the right one. LOOKUP CLAUSE BUILDER Hover any `| lookup` command to open a visual editor for that clause: - See every field the lookup actually contains, with sample values. - Change the match field, edit AS aliases, and check/uncheck OUTPUT fields. - Type a value against a match field to live-preview the exact row the lookup would return. - Apply writes the rewritten clause back into your search — safely: if the line changed since you hovered, the edit is refused instead of corrupting your SPL. COPY ANYTHING One-click copy icons for field names and values, everywhere you need them: - Statistics and dashboard table headers - Events table (View: Table) column headers, including _time - The field info dialog — field name and each listed value (copies the full raw value even when the display truncates it) - Field and sample cells in the hover popups CONFIGURABLE Every feature has an on/off toggle on the options page, including a switch that disables all search-dispatching functionality (sample fetch and live preview) for a passive, read-only mode. PRIVACY & SCOPE - Runs only on *.splunkcloud.com pages. - All requests are same-origin calls to your own Splunk stack using your existing session — no external servers, no analytics, no telemetry, no data collection. Your searches and lookup data never leave your browser. - Sample data and live preview run small oneshot searches (| inputlookup … | head 1) under your account; this is the feature the read-only toggle disables. REQUIREMENTS & NOTES - Built for Splunk Cloud (Splunk Web on *.splunkcloud.com). - "Edit lookup" deep links require the Lookup File Editor app on your stack; everything else works without it. - Some navigation URLs vary between Splunk versions — if an edit link 404s on your stack, please file an issue with the working URL from your Settings pages. This extension is an independent project and is not affiliated with, endorsed by, or sponsored by Splunk LLC or Cisco. Splunk is a registered trademark of Splunk LLC.
Aug 29, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.