Splunk Enterprise

How to change color of a panel from a field in lookup table?

hq
Loves-to-Learn Lots

I am trying to change color of a one row of a panel ONLY if it is found in the lookup table. For example, if I have a lookup table with websites not allowed on the company, and a panel that has all websites accessed. Then I would like to see the color Red be for the rows where the website is part of the lookup table AND on the panel.  I would still like to see all the results as well, just the changed color for the ones that are in the lookup table. Is there any way for me to do this?

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If there is a second column in the lookup table with values for all the domains you want to flag, you can do an inputlookup and append an extra multi-value element to all the columns with value "RED" for example, then use CSS to hide the multi-value in the table.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...