- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Highlighting a field in the events output
whywhywhy
Engager
07-23-2010
09:12 PM
I have a search that is looking pipes through a rex.
rex fields=_raw "\D(?<big_num>\d{15,16})\D"
I want the UI to highlight the values identified as feild type big_num in the events log. Is there a way to do this?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ftk
Motivator
08-09-2010
05:02 PM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
simuvid

Splunk Employee
07-26-2010
01:22 PM
Hi There,
what you can do is extract a custom field for the value in the events you are looking for.
See documentation here:
http://www.splunk.com/base/Documentation/4.1.4/User/ExtractNewFields
When you add the field to your UI from the field picker on the left hand side, the value is shown and also highlighted.
Hope that's what you are looking for.
Cheers,
Christian
