Splunk Search

Why SPL syntax highlighting not working correctly?

Hoekb03
Explorer

Hi,

I've created this rather complicated piece of SPL. To make it a bit more understandable I added some comment lines. In the screenshot you can see the SPL syntax highlighting stops working correctly from line #20. The strange thing is that when I remove line 20 all together it works fine, and there are more comment lines further on. Whatever comment I put on that position causes this behaviour. 

Hoekb03_2-1658741735482.png

Line removed, it works fine:

Hoekb03_3-1658742001878.png

Comment ```test comment``` breaks the thing down again. 

Hoekb03_4-1658742080743.png

It's just a minor cosmetic thing, but I'd like to know what's happening here and why. We're using splunk Enterprise 8.1.10.1 on my site. Any thoughts appreciated!

 

 

 

 

 

 

Tags (2)
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @Hoekb03 ... I am using Splunk 8.2.5 and its SPL highlighting working fine even after 20 lines. Are you using older versions ah?!?!

Splunk 8.2.5.png

View solution in original post

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Hoekb03 ... I am using Splunk 8.2.5 and its SPL highlighting working fine even after 20 lines. Are you using older versions ah?!?!

Splunk 8.2.5.png

Tags (1)
0 Karma

Hoekb03
Explorer

It's not that highlighting stops after 20 lines, in my case there are comment lines after line 20, when I remove the line on 20 the rest works fine. Syntax auto fill also stops working in my example I just noted. I tried it at home where I use 9.0 with no problem at all. I'll just wait for a new version @ the office.  I'll accept your answer for now.

0 Karma

Hoekb03
Explorer

My query doesn't do the trick btw, still curious about the cause of the highlighting not working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...