Splunk Search

Specific keyword based colour

jerinvarghese
Communicator

Hi Team,

need help in getting few nodelabel highlighted.  "WANRT"  & "DCNDC".

sitecodenodelabel
PJSLANCUA001
PCWLANCUA001
PCWWANINF001
PCWWANRTC001
PCWDCNDCI001

 

Below is the code that I used to get the "WANRT" devices highlighted with RED color, but i am unable to get the "DCNDC" devices too. 

 

 

        <format type="color" field="nodelabel">
          <colorPalette type="expression">if (like(value,"%WANRT%"),"#FF5733","#FFFFFF")</colorPalette>
        </format>

 

 

please help me with the code to get both highlighted.

Labels (5)

richgalloway
SplunkTrust
SplunkTrust

Have you tried this?

<format type="color" field="nodelabel">
  <colorPalette type="expression">
if (like(value,"%WANRT%") OR like(value, "DCNDC%"),"#FF5733","#FFFFFF")</colorPalette>
</format>
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...