<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does highlight not highlight? What am I doing wrong? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126990#M34419</link>
    <description>&lt;P&gt;Yes, the word user shows up in yellow highlighting when part of "user=admin".  Likewise:&lt;/P&gt;

&lt;P&gt;index=_audit action=search | highlight user info fields&lt;/P&gt;

&lt;P&gt;Highlights each instance of "user" "info" and "fields".&lt;/P&gt;

&lt;P&gt;Sounds like you may have a bug?  What exact version of Splunk are you using?&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jul 2014 18:58:10 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2014-07-02T18:58:10Z</dc:date>
    <item>
      <title>Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126987#M34416</link>
      <description>&lt;P&gt;This should be dead simple. Obviosuly I am missing something.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;host=tcserver1 | highlight ERROR&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I just want a pretty color for anywhere the string "error" shows up in the logs as I watch them scroll by. I don't &lt;EM&gt;only&lt;/EM&gt; want to see the events with "error", I need to see all of them, but need to be able to visually pick out the ones WITH error when they happen.&lt;/P&gt;

&lt;P&gt;The &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.2/SearchReference/Highlight"&gt;highlight&lt;/A&gt; search command seems really straight forward, I can't imagine what I am missing here... I can use CTRL+F to see that there are plenty of instances of this string, but I get no highlighting using the search command.  &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 17:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126987#M34416</guid>
      <dc:creator>neiljpeterson</dc:creator>
      <dc:date>2014-07-01T17:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126988#M34417</link>
      <description>&lt;P&gt;In my case, a bit of testing shows that the highlight only works on the Events page on the raw data, not on the Statistics page.  So, if you are doing any statistics or creating a table the highlighting doesn't seem to apply.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 18:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126988#M34417</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2014-07-01T18:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126989#M34418</link>
      <description>&lt;P&gt;I am on the events page, looking at the _raw. Nothing fancy. &lt;/P&gt;

&lt;P&gt;Try this search:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=_audit action=search | highlight user&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Does that change how "user" or the user field looks in the results? Cause it does nothing for me.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 18:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126989#M34418</guid>
      <dc:creator>neiljpeterson</dc:creator>
      <dc:date>2014-07-02T18:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126990#M34419</link>
      <description>&lt;P&gt;Yes, the word user shows up in yellow highlighting when part of "user=admin".  Likewise:&lt;/P&gt;

&lt;P&gt;index=_audit action=search | highlight user info fields&lt;/P&gt;

&lt;P&gt;Highlights each instance of "user" "info" and "fields".&lt;/P&gt;

&lt;P&gt;Sounds like you may have a bug?  What exact version of Splunk are you using?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 18:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126990#M34419</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2014-07-02T18:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126991#M34420</link>
      <description>&lt;P&gt;I can not get "highlight" or "iconify" to do anything in Splunk 6.3&lt;/P&gt;

&lt;P&gt;An example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=*someapp* sourcetype=*iis* | highlight c_ip
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Dec 2016 01:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126991#M34420</guid>
      <dc:creator>bareisd</dc:creator>
      <dc:date>2016-12-07T01:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126992#M34421</link>
      <description>&lt;P&gt;Maybe you could change the view to "Raw" or "List", the string you highlight will be in yellow.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 02:09:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126992#M34421</guid>
      <dc:creator>kenkenou</dc:creator>
      <dc:date>2016-12-07T02:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why does highlight not highlight? What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126993#M34422</link>
      <description>&lt;P&gt;It would be nice to be able to specify a colour but I'd be happy if anything worked.  &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I am in "raw" mode.&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;I have discovered that I can highlight text (as OP wanted) but not fields, for example to "fix" the original example, this would work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=tcserver1 | highlight "ERROR"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As it would highlight the text "ERROR" wherever it was found.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 20:20:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-highlight-not-highlight-What-am-I-doing-wrong/m-p/126993#M34422</guid>
      <dc:creator>bareisd</dc:creator>
      <dc:date>2016-12-07T20:20:02Z</dc:date>
    </item>
  </channel>
</rss>

