Hi
I have a simple search as following
index=myindex "access denied"
When I run this in search, as results returned, "access denied" is highlighted, save the search as a report, run it, search phrase also highlighted, but if I save the search as a dashboard, the search phrase no longer highlighted, how can I make search phrase highlighted in the dashboard?
Thanks
Dong
Use the highlight command. Also, make sure you are viewing "raw" events in your visualization. See the screenshot below:
See this answer for more information -> https://answers.splunk.com/answers/595074/how-to-highlight-events-in-panel-of-dashboard-base.html