<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk Search Assistant highlighting certain words from my description in green color? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512876#M34214</link>
    <description>&lt;P&gt;I replicated this issue with Splunk versions 7.2 and 8.0.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2020 20:00:46 GMT</pubDate>
    <dc:creator>malvidin</dc:creator>
    <dc:date>2020-08-06T20:00:46Z</dc:date>
    <item>
      <title>Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/472370#M31011</link>
      <description>&lt;P&gt;I am using &lt;STRONG&gt;searchbnf.conf&lt;/STRONG&gt; file to provide help on my custom search commands but the search assistant is highlighting certain words from my description in green color which is not intended. How can I disable this or are there any escape characters I can use to ask Splunk to not highlight this?&lt;/P&gt;

&lt;P&gt;Here's what my search assistant is showing:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8128iC515A25370E0FCD7/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;And here is the entry in my &lt;STRONG&gt;searchbnf.conf&lt;/STRONG&gt; file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[snxapiquota-command]
syntax = snxapiquota
description = Find information about your API quota, like current usage, quota left etc.
example = | snxapiquota
usage = public
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Dec 2019 11:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/472370#M31011</guid>
      <dc:creator>umairahmad3985</dc:creator>
      <dc:date>2019-12-24T11:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/472371#M31012</link>
      <description>&lt;P&gt;@umairahmad3985  unable to replicate it on Splunk7.3.4. What Splunk version are you running ? &lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 00:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/472371#M31012</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-03-17T00:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512849#M34211</link>
      <description>&lt;P&gt;It appears to happen with all uppercase words. I have not found a way around it yet.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 19:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512849#M34211</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-08-06T19:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512862#M34213</link>
      <description>&lt;P&gt;I tried the following, with no luck.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;AAAA _BBBB_ \CCCC "DDDD" 'EEEE' `FFFF`&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="uppercase_highlight.png" style="width: 261px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10090i7A099637A3FF5970/image-size/large?v=v2&amp;amp;px=999" role="button" title="uppercase_highlight.png" alt="uppercase_highlight.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I was surprised to see backslashes escaped, and the underscore after BBBB is highlighted but the underscore after is not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 19:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512862#M34213</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-08-06T19:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512876#M34214</link>
      <description>&lt;P&gt;I replicated this issue with Splunk versions 7.2 and 8.0.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 20:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512876#M34214</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-08-06T20:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512877#M34215</link>
      <description>&lt;P&gt;That’s because the command is not developed by Splunk. Its 3rd party command.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 20:06:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512877#M34215</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-06T20:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512882#M34216</link>
      <description>&lt;P&gt;I think there is a misunderstanding. This is a discussion on how the Splunk searchbnf.conf parser has undocumented and unwanted behavior, not about any particular app or any 3rd party commands.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 20:21:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/512882#M34216</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-08-06T20:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/513033#M34232</link>
      <description>&lt;P&gt;For the highlighting, it appears that it has affected Splunk as well.&amp;nbsp; You can look at the shelper response to see the raw text, so the highlighting appears to be in the browser, not in the backend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Note: if you want to use the "or" ("|") command

regex (field("="|"!="))?((\")?string(\")?)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="malvidin_1-1596814209209.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10107iD856E2647F8D8568/image-size/large?v=v2&amp;amp;px=999" role="button" title="malvidin_1-1596814209209.png" alt="malvidin_1-1596814209209.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you look at the chart command, it does the same to the BY/OVER that is capitalized in the source.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malvidin_0-1596815378048.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10108iF2703A05F0A4A358/image-size/medium?v=v2&amp;amp;px=400" role="button" title="malvidin_0-1596815378048.png" alt="malvidin_0-1596815378048.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 15:50:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/513033#M34232</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-08-07T15:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/514498#M34370</link>
      <description>&lt;P&gt;The default searchbnf.conf file located here in&amp;nbsp;&lt;EM&gt;$SPLUNK_HOME/etc/system/default&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Says this:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;UPPERCASETERMS and quoted terms are put into &amp;lt;code/&amp;gt;&lt;/P&gt;&lt;P&gt;So when you have something like CSV, PDF, "myindex" the text appears in green color.&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Laura Stewart&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Principal Technical Writer&amp;nbsp;–&amp;nbsp;Search Processing Language (SPL)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 16:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/514498#M34370</guid>
      <dc:creator>lstewart_splunk</dc:creator>
      <dc:date>2020-08-17T16:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Search Assistant highlighting certain words from my description in green color?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/514512#M34377</link>
      <description>&lt;P&gt;That is there, under the "DESCRIPTION FORMATTING" section.&lt;/P&gt;&lt;P&gt;The earlier "FORMATTING" section states to &lt;STRONG&gt;use \" to represent a quote.&amp;nbsp;&lt;/STRONG&gt;This is not directly aligned with the Description Formatting and does not work in a description.&lt;/P&gt;&lt;P&gt;The "\" is also shown as "\\", which is not documented.&lt;/P&gt;&lt;P&gt;Based on the descriptions shown above that were written by Splunk, it appears that this behavior was not understood by Splunk authors, or the parsing behavior changed and the descriptions were not updated.&lt;/P&gt;&lt;P&gt;The only concern I have with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/96825"&gt;@lstewart_splunk&lt;/a&gt;'s accurate answer, is that&amp;nbsp;the current behavior breaks the description syntax for stock Splunk commands, as shown above for regex.&amp;nbsp; The Splunk authors for the regex syntax apparently expected that (\")?string(\")? would be shown as (")?string(")?, but instead, it is strangely highlighted.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 18:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-Splunk-Search-Assistant-highlighting-certain-words-from/m-p/514512#M34377</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-08-17T18:28:19Z</dc:date>
    </item>
  </channel>
</rss>

