<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Icons for severities in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77249#M181528</link>
    <description>&lt;P&gt;How to add an icon associated with the severity in the start of each event in the search, just like the Cisco CNA System Messages? Or at least make each event with a background color associated with the severity? Is there an app for that?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2011 18:17:35 GMT</pubDate>
    <dc:creator>drpsycho</dc:creator>
    <dc:date>2011-09-16T18:17:35Z</dc:date>
    <item>
      <title>Icons for severities</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77249#M181528</link>
      <description>&lt;P&gt;How to add an icon associated with the severity in the start of each event in the search, just like the Cisco CNA System Messages? Or at least make each event with a background color associated with the severity? Is there an app for that?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:17:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77249#M181528</guid>
      <dc:creator>drpsycho</dc:creator>
      <dc:date>2011-09-16T18:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Icons for severities</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77250#M181529</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;have a look here, but it will requires some web development knowledge, but it works:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Developer/UseCSS"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Developer/UseCSS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2012 20:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77250#M181529</guid>
      <dc:creator>Mathieu_Dessus</dc:creator>
      <dc:date>2012-02-05T20:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Icons for severities</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77251#M181530</link>
      <description>&lt;P&gt;You could use the iconify search command.&lt;/P&gt;

&lt;P&gt;So if you extract the severity level out into a field named  "severity", you could do something like :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yourinitialsearch | iconify severity
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Iconify"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Iconify&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2012 23:22:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Icons-for-severities/m-p/77251#M181530</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2012-02-05T23:22:58Z</dc:date>
    </item>
  </channel>
</rss>

