Building for the Splunk Platform

How to apply the field color on the table results with multi-value fields based on the first value


Is it possible to apply the color based on the first value on the multi-value fields?

Below is the sample data. If the first value of server_status is Online then the field color should turn into green else the color will be red.

Offline (31 days ago)
server101Offline (31 days ago)

Labels (1)
0 Karma


You can change the background rather than the font colour using colorPalette - add another multivalue with a value representing the colour you want used, then use CSS to hide the extra value.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...