Splunk Search

How to apply color to a field with multiple values appended together?

kavyamohan
Explorer
JobExecutionTime
2652.180000
3462.840000
823.780000

I have a field named JobExecutionTime and i have it as a list of values not as seperate rows, How Can i apply color to the values based on some range. I have tried colorpalette rangemap but none seems to work but for seperate rows it is working(by which i mean is that if it is a single row with all values appended rangemap and color palette is not working. However if i have multiple rows with one value in each row rangemap and colorpalette is working). I do not need js and css as it won't be able for client to edit if they need to change the range.

0 Karma

aberkow
Builder

What would you want the range to be? I would imagine you either want to take the min, max, or average in a stats command, or you would want to separate each of these into their own rows with an mvexpand command. I don't know if applying a single value range over a multivalue field makes sense to Splunk

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...