I built a search like this
sourcetype=firewall rule=100 | search drop OR accept | head 1
This shows my only the last event (drop or accept).
Now I want to visualize with a colored single value field. For "drop" it should going red, for accept it should going green.
How can I realize that?
Thank you very much!
Further to Ayns answer, you don't need to do a | search after your searchterms, they are all search terms. Just do a sourcetype=firewall rule=100 drop OR accept | head etc