Splunk Search

How to color code a field value based on the newly created field?

yvassilyeva
Path Finder

Hi!

I have a table created with Splunk search with the name of the site and projects with due dates that looks like this:

SITEMARCHAPRILMAY
site1project1 project2
site2project2  
site3 project3 

some projects are past due and some are in good standing. to determine whether it is past due i simply do an eval statement:

|eval past_due=if(strptime(task_duedate,"%Y-%m-%d") < relative_time(now(), "@d"),1,0) 

Other projects are in good standing. Can I color code the fields with project that are past due with red, and projects that are good standing green?

Thank you!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...