Hi,
I built a search like this
sourcetype=firewall rule=100 | search drop OR accept | head 1
This shows my only the last event (drop or accept).
Now I want to visualize with a colored single value field. For "drop" it should going red, for accept it should going green.
How can I realize that?
Thank you very much!
Regards
Further to Ayns answer, you don't need to do a | search after your searchterms, they are all search terms. Just do a sourcetype=firewall rule=100 drop OR accept | head etc
This is covered in the docs: http://docs.splunk.com/Documentation/Splunk/latest/Developer/AddASingleButton#Set_the_color_of_the_p...