I want to make rows in red color of a search output If some condition met like my search is
index="siebel_mon" SourceName=Siebel Message="Siebel 7 -" |fields _time,siebel_message,EventCode
, So in search output the row should be in red color If EventCode=113.
Please help me on this.
-Kamal
If you want to color your search result, you can use rangemap or eventtype with css. You can refer to following answer.
http://splunk-base.splunk.com/answers/8775/configure-colour-coded-results-by-default
Hope this help.
Check out the following app:
Splunk 6.x Dashboard Examples (https://apps.splunk.com/app/1603/)
This app includes an example, "Table Row Highlighting", that may be copied/used for your purposes.
Some things you'll need to do:
Example source:
<dashboard script="table_row_highlighting.js" stylesheet="table_decorations.css">
<label>Table Row Highlighting</label>
<row>
<table id="highlight">
<title>Row Coloring</title>
<searchString>index=_internal sourcetype=splunkd component=Metrics group=search_concurrency | eval user=coalesce(user, "system total") | bucket _time span=1h | stats avg(active_hist_searches) as active_hist_searches avg(active_realtime_searches) as active_realtime_searches by _time,user</searchString>
<earliestTime>-24h</earliestTime>
<option name="drilldown">none</option>
</table>
</row>
</dashboard>
If you want to color your search result, you can use rangemap or eventtype with css. You can refer to following answer.
http://splunk-base.splunk.com/answers/8775/configure-colour-coded-results-by-default
Hope this help.