Splunk Enterprise

How to change color of a panel from a field in lookup table?

hq
Loves-to-Learn Lots

I am trying to change color of a one row of a panel ONLY if it is found in the lookup table. For example, if I have a lookup table with websites not allowed on the company, and a panel that has all websites accessed. Then I would like to see the color Red be for the rows where the website is part of the lookup table AND on the panel.  I would still like to see all the results as well, just the changed color for the ones that are in the lookup table. Is there any way for me to do this?

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If there is a second column in the lookup table with values for all the domains you want to flag, you can do an inputlookup and append an extra multi-value element to all the columns with value "RED" for example, then use CSS to hide the multi-value in the table.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...