Reporting

Add color to report column in email

JasonMcMahan
Explorer

I have created a search which has multiple columns. One of the columns called status has color formatting.
ALert = Red, Disiabled=Blue, Success=Green.

The formatting works fine in the search however when the email is received there is no coloring at all.

Is it possible to add to coloring so it appears as it does in the search > report?

 

Also we are using splunk web not on premise.

Thank you

Labels (3)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

EDIT >> we are using Splunk web///

do you use splunk cloud, if yes, then, you will need to contact the splunk cloud support guys to edit/update the conf files.  << EDIT


i think you saved this as an alert and you get email from the alert, right.

if so, maybe, please check dashboards/reports options, instead of the "alerts".

 

Sending colored table on email report is a difficult task i think. 

the best and easy workaround is the dashboards. 

dashboard's pdf email delivery is possible with colored tables. 

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @JasonMcMahan ... i am not sure of your query, but, pls have a look at a similar query...

https://community.splunk.com/t5/All-Apps-and-Add-ons/Change-background-color-of-specifc-column-in-em...

 

0 Karma

JasonMcMahan
Explorer

Thank you, as we are using Splunk web i am not sure that option could work.

the query is.

index=Index sourcetype=WinHostMon source="service" host="*" DisplayName="Bits*" 
| rename DisplayName AS ServiceName 
| rename State AS Status 
| eval host = lower(host) 
| lookup ourhosts_env host OUTPUTNEW Environment 
| rename host as Host 
| eval Time = strftime(_time, "%Y-%d-%m %H:%M:%S") 
| fields - _time 
| eval CurrentStatus = case(StartMode == "Disabled" AND Status == "Stopped", "Disabled", StartMode == "Auto" AND Status == "Running", "Success", StartMode == "Auto" AND Status == "Stopped", "Failure", StartMode == "Auto" AND Status == "Stopped", "Failure")
| stats latest(Time) as Time latest(Status) as Status latest(StartMode) as StartMode by Host ServiceName Environment CurrentStatus
| table Time Environment Host Status StartMode CurrentStatus

When i run the search, or the report the colored cells show red, yellow, green. The email just has plain table no color.

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

EDIT >> we are using Splunk web///

do you use splunk cloud, if yes, then, you will need to contact the splunk cloud support guys to edit/update the conf files.  << EDIT


i think you saved this as an alert and you get email from the alert, right.

if so, maybe, please check dashboards/reports options, instead of the "alerts".

 

Sending colored table on email report is a difficult task i think. 

the best and easy workaround is the dashboards. 

dashboard's pdf email delivery is possible with colored tables. 

0 Karma

JasonMcMahan
Explorer

You are correct Splunk cloud, unfortunately i am only a mere power user not admin. LoL

But can run it past the admin to see if he will.

I originally had the search, saved as a report then scheduled it to run daily because one of our team members like it delivered to his in box instead of the dashboard.

Sadly though you confirmed what i was afraid of about the coloring. I had read send it as pdf could save the color but I was hoping to just have it inserted.

I appreciate your help even though it only confirmed what i was hoping not to do.

 

Have a wonderful day.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...