Deployment Architecture

Why is search syntax highlighting not working in splunk 6.4.2 Enterprise edition?

samnathan
Explorer
  1. There is no "Account Settings>Preferences" under User Icon (Splunk Bar in 6.4.2)
  2. I have added "local" directory under $SPLUNK_HOME/etc/apps/search/
  3. Created file user-prefs.conf.spec.in (by copying user-prefs.conf under$SPLUNK_HOME/etc/apps/search/default)
  4. Opened the $SPLUNK_HOME/etc/apps/search/user-prefs.conf.spec.in/ and added the following: search_syntax_highlighting = true search_auto_format = false search_line_numbers = false
  5. Restarted the Splunk instance
  6. Search syntax highlighting doesn't work

Does this work only in higher versions? Please note it's not a free license version. Kindly help!

Tags (1)
0 Karma
1 Solution

jluo_splunk
Splunk Employee
Splunk Employee

Hi Samnathan,

Syntax highlighting was introduced in Splunk 6.6, which is why it won't work.

View solution in original post

0 Karma

jluo_splunk
Splunk Employee
Splunk Employee

Hi Samnathan,

Syntax highlighting was introduced in Splunk 6.6, which is why it won't work.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...