Deployment Architecture

Why is search syntax highlighting not working in splunk 6.4.2 Enterprise edition?

samnathan
Explorer
  1. There is no "Account Settings>Preferences" under User Icon (Splunk Bar in 6.4.2)
  2. I have added "local" directory under $SPLUNK_HOME/etc/apps/search/
  3. Created file user-prefs.conf.spec.in (by copying user-prefs.conf under$SPLUNK_HOME/etc/apps/search/default)
  4. Opened the $SPLUNK_HOME/etc/apps/search/user-prefs.conf.spec.in/ and added the following: search_syntax_highlighting = true search_auto_format = false search_line_numbers = false
  5. Restarted the Splunk instance
  6. Search syntax highlighting doesn't work

Does this work only in higher versions? Please note it's not a free license version. Kindly help!

Tags (1)
0 Karma
1 Solution

jluo_splunk
Splunk Employee
Splunk Employee

Hi Samnathan,

Syntax highlighting was introduced in Splunk 6.6, which is why it won't work.

View solution in original post

0 Karma

jluo_splunk
Splunk Employee
Splunk Employee

Hi Samnathan,

Syntax highlighting was introduced in Splunk 6.6, which is why it won't work.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...