Reporting

Add color to report column in email

JasonMcMahan
Explorer

I have created a search which has multiple columns. One of the columns called status has color formatting.
ALert = Red, Disiabled=Blue, Success=Green.

The formatting works fine in the search however when the email is received there is no coloring at all.

Is it possible to add to coloring so it appears as it does in the search > report?

 

Also we are using splunk web not on premise.

Thank you

Labels (2)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

EDIT >> we are using Splunk web///

do you use splunk cloud, if yes, then, you will need to contact the splunk cloud support guys to edit/update the conf files.  << EDIT


i think you saved this as an alert and you get email from the alert, right.

if so, maybe, please check dashboards/reports options, instead of the "alerts".

 

Sending colored table on email report is a difficult task i think. 

the best and easy workaround is the dashboards. 

dashboard's pdf email delivery is possible with colored tables. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @JasonMcMahan ... i am not sure of your query, but, pls have a look at a similar query...

https://community.splunk.com/t5/All-Apps-and-Add-ons/Change-background-color-of-specifc-column-in-em...

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

JasonMcMahan
Explorer

Thank you, as we are using Splunk web i am not sure that option could work.

the query is.

index=Index sourcetype=WinHostMon source="service" host="*" DisplayName="Bits*" 
| rename DisplayName AS ServiceName 
| rename State AS Status 
| eval host = lower(host) 
| lookup ourhosts_env host OUTPUTNEW Environment 
| rename host as Host 
| eval Time = strftime(_time, "%Y-%d-%m %H:%M:%S") 
| fields - _time 
| eval CurrentStatus = case(StartMode == "Disabled" AND Status == "Stopped", "Disabled", StartMode == "Auto" AND Status == "Running", "Success", StartMode == "Auto" AND Status == "Stopped", "Failure", StartMode == "Auto" AND Status == "Stopped", "Failure")
| stats latest(Time) as Time latest(Status) as Status latest(StartMode) as StartMode by Host ServiceName Environment CurrentStatus
| table Time Environment Host Status StartMode CurrentStatus

When i run the search, or the report the colored cells show red, yellow, green. The email just has plain table no color.

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

EDIT >> we are using Splunk web///

do you use splunk cloud, if yes, then, you will need to contact the splunk cloud support guys to edit/update the conf files.  << EDIT


i think you saved this as an alert and you get email from the alert, right.

if so, maybe, please check dashboards/reports options, instead of the "alerts".

 

Sending colored table on email report is a difficult task i think. 

the best and easy workaround is the dashboards. 

dashboard's pdf email delivery is possible with colored tables. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

JasonMcMahan
Explorer

You are correct Splunk cloud, unfortunately i am only a mere power user not admin. LoL

But can run it past the admin to see if he will.

I originally had the search, saved as a report then scheduled it to run daily because one of our team members like it delivered to his in box instead of the dashboard.

Sadly though you confirmed what i was afraid of about the coloring. I had read send it as pdf could save the color but I was hoping to just have it inserted.

I appreciate your help even though it only confirmed what i was hoping not to do.

 

Have a wonderful day.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...