Splunk Search
Highlighted

Highlighting a field in the events output

Engager

I have a search that is looking pipes through a rex.

rex fields=_raw "\D(?<big_num>\d{15,16})\D"

I want the UI to highlight the values identified as feild type big_num in the events log. Is there a way to do this?

Tags (2)
Highlighted

Re: Highlighting a field in the events output

Splunk Employee
Splunk Employee

Hi There,

what you can do is extract a custom field for the value in the events you are looking for.

See documentation here:

http://www.splunk.com/base/Documentation/4.1.4/User/ExtractNewFields

When you add the field to your UI from the field picker on the left hand side, the value is shown and also highlighted.

Hope that's what you are looking for.

Cheers,

Christian

Highlighted

Re: Highlighting a field in the events output

Motivator

You can use the highlight and iconify search commands in order highlight specific words or fields in your events.

0 Karma