Dashboards & Visualizations

How to highlight a table cell based on query?

ednk
Explorer

i have a table

case id severity open date status age
3241765 critical 6/5/2022 awaiting 30 days
9847636 high  1/6/2022 pending 5 days

 

i want to highlight the table by queries like those:

if severity=critical AND status=awaiting or pending - highlight the values critical and awaiting in red

if severity=critical AND status=awaiting or pending more than 30 days- highlight the row in red

if case is open more then 30 days - mark the cell in red.

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
0 Karma

ednk
Explorer

yes, 

 I didn't find a solution ,

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What did you try exactly?

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...