Splunk Search

How to apply color to a field with multiple values appended together?

kavyamohan
Explorer
JobExecutionTime
2652.180000
3462.840000
823.780000

I have a field named JobExecutionTime and i have it as a list of values not as seperate rows, How Can i apply color to the values based on some range. I have tried colorpalette rangemap but none seems to work but for seperate rows it is working(by which i mean is that if it is a single row with all values appended rangemap and color palette is not working. However if i have multiple rows with one value in each row rangemap and colorpalette is working). I do not need js and css as it won't be able for client to edit if they need to change the range.

0 Karma

aberkow
Builder

What would you want the range to be? I would imagine you either want to take the min, max, or average in a stats command, or you would want to separate each of these into their own rows with an mvexpand command. I don't know if applying a single value range over a multivalue field makes sense to Splunk

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...