JSON Expander Bookmarklet
Splunk search in any modern browser
Expands every collapsed JSON field in a Splunk search event with one click, then highlights the event and scrolls it into view.
@@shots https://cdn.prod.website-files.com/654c082e33faa8130383d311/6ac9e9e2be08e27a23436b41_vsc-1-extensions.webp | A Splunk search with a nested JSON event fully expanded, and the 《 JSON 》for SPL bookmarklet in the browser's bookmarks bar @@specs Browsers | Chrome, Firefox, Edge and Safari ;; Install | A browser bookmark. No extension or permissions ;; Splunk | Splunk Enterprise and Splunk Cloud ;; License | Apache 2.0 ;; Source | zuykn/BM-json_expander -> https://github.com/zuykn/BM-json_expander
Overview
Reading nested JSON in Splunk usually means clicking [+] over and over, event after event. JSON Expander opens every collapsed field in the next JSON event with one click, highlights it and scrolls it into view. Click again for the next event.
It runs as a browser bookmarklet, so there is no extension to install, no permissions to grant and nothing to change in Splunk.
Features
- Expands every collapsed JSON field in an event with one click
- Highlights the expanded event and scrolls it into view
- Finds the next collapsed event from the top of the page down
- Shows a notice once every event is expanded
- No extension, install or permissions: it's a bookmark
- Works with Splunk Enterprise and Splunk Cloud
- Chrome, Firefox, Edge and Safari
Use Cases
- Read nested JSON events during incident response without clicking through every field
- Review cloud, API and security logs that arrive as deeply nested JSON
- Step through search results one event at a time, each highlighted as it opens
Get Started
- Drag the 《 JSON 》for SPL link at the top of this page to your bookmarks bar, or copy the code from GitHub into a new bookmark.
- Run a Splunk search that returns JSON events.
- Click the bookmark to expand the next collapsed event. Click again for the one after it.
Safari: turn on “Allow JavaScript from Smart Search field” under Settings, Developer.
Details
Version
v1.0.0 · Nov 2025
Works with
Splunk search in any modern browser
Questions or a Custom Version?
The engineers who built it can help you deploy it, tune it to your environment, or build what you need next.
Talk to Our Team →Need Help Getting It Running?
We can deploy it across your organization, tune it to your environment, or build something new around it.
Book a Call →