Building for the Splunk Platform

How to apply the field color on the table results with multi-value fields based on the first value

kelz
Explorer

Is it possible to apply the color based on the first value on the multi-value fields?

Below is the sample data. If the first value of server_status is Online then the field color should turn into green else the color will be red.

hostnameserver_status
server101Online
Offline (31 days ago)
  
  
hostnameserver_status
server101Offline (31 days ago)
Online




Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can change the background rather than the font colour using colorPalette - add another multivalue with a value representing the colour you want used, then use CSS to hide the extra value.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...