Splunk Enterprise

How to color the field value based on the value present in another field?

Ashwini008
Communicator

Hi,

I want to color the filename value (.i.e Account) with red color , if the value present in another fields is blank. How can i do? preferably  using xml code....

filename

application

ID

Status

Account

 

 

 

Account1

spear

Ydg123

p

0 Karma

ITWhisperer
Ultra Champion

See my answer here  Essentially, you make the field you want to colour a multi-value field with a value that you configure to be mapped to the colour you want, then you hide (display: none;) the additional value.

0 Karma