Splunk Search

How to dynamically remove a field from search & how to dynamically use threshold from lookup file and change color based on it?

niks987
Explorer

Hi All,

Hope you all are doing good.

I am stuck with 2 questions may be due to my Splunk query knowledge, hope you allcan help me in resolving the same.

Question 1:-
I have to dynamically remove a Responsetime field from a search when ComponentName is XYZ. I treid using if command splunk fields is not supported in it i believe. We are getting the ComponentName from drilldown via a token.

Question 2:-
I have to dynamically change the color of a panel based on the threshold value from a lookup table. Example:-
for ComponentName=xyz the threshold is 900 than the color should should be changed when threshold > 900 to red and threshold <900 to green.

Please do let me know if you any questions.

Thanks for your help 🙂

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...