Dashboards & Visualizations

How to color all the fields of a table based on the same rule

JulienKVT
Engager

Hello, I have a table based on a query to collect any kind of services status and format it using xyserie
From a server to another the service collected are not the same so I can't/don't want to set 50/80 columns one by one with the rule Running/Stopped. 

Then I tried to modify the code but I can't find any doc where it is explained in detail. 

Only success: I found and set a unique rule "StatusColumnFormatConfig" in my code. So each field could apply to this rule

but then I'd like to apply it for all columns but I can't find how to do it... 

As you can see in the example I just tried a "*" but of course it was to simple to work 🙂

Second step would be to put the host name in Green if everything is Running and Red is only one is Stopped but I guess I will need another calculated field for that. 

Thank you by advance


Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...