I have a search that is looking pipes through a rex.
rex fields=_raw "\D(?<big_num>\d{15,16})\D"
I want the UI to highlight the values identified as feild type big_num in the events log. Is there a way to do this?
Hi There,
what you can do is extract a custom field for the value in the events you are looking for.
See documentation here:
http://www.splunk.com/base/Documentation/4.1.4/User/ExtractNewFields
When you add the field to your UI from the field picker on the left hand side, the value is shown and also highlighted.
Hope that's what you are looking for.
Cheers,
Christian