Splunk Search

How to color code the results in a table column if the values are above a certain number?

shrey12
Explorer

If i have a search that gives me the result as follows, I want to flag a red color in the values of the delta column if the delta is more than say 2. How can i do that?

Power1 &nbsp&nbsp&nbsp Power2 &nbsp&nbsp&nbsp abs(Delta)
12&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp12&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp0
23&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp20&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp3(should be in red color)
44&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp40&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp&nbsp4(should be in red color)

0 Karma

LukeMurphey
Champion

There are several options here:

Option 1: range map in a table
See the Splunk dashboard examples app for some examples of how to do this. Specifically, you will want to check out “Table Icon Set (Rangemap)”.

Option 2: use a custom cell renderer

See the accepted answer for this question. It uses some custom Javascript but isn't too bad. It will only work on Splunk 6.0+.

Option 3: use custom CSS
See the accepted answer for this question. It also uses some custom Javascript but it is easy to use. This will work on Splunk 5.0 too.

0 Karma

shrey12
Explorer

How can do this with with just sideview utils by adding modules and changing parameters

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...