Splunk Search

Why SPL syntax highlighting not working correctly?

Hoekb03
Explorer

Hi,

I've created this rather complicated piece of SPL. To make it a bit more understandable I added some comment lines. In the screenshot you can see the SPL syntax highlighting stops working correctly from line #20. The strange thing is that when I remove line 20 all together it works fine, and there are more comment lines further on. Whatever comment I put on that position causes this behaviour. 

Hoekb03_2-1658741735482.png

Line removed, it works fine:

Hoekb03_3-1658742001878.png

Comment ```test comment``` breaks the thing down again. 

Hoekb03_4-1658742080743.png

It's just a minor cosmetic thing, but I'd like to know what's happening here and why. We're using splunk Enterprise 8.1.10.1 on my site. Any thoughts appreciated!

 

 

 

 

 

 

Tags (2)
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @Hoekb03 ... I am using Splunk 8.2.5 and its SPL highlighting working fine even after 20 lines. Are you using older versions ah?!?!

Splunk 8.2.5.png

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Hoekb03 ... I am using Splunk 8.2.5 and its SPL highlighting working fine even after 20 lines. Are you using older versions ah?!?!

Splunk 8.2.5.png

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (1)
0 Karma

Hoekb03
Explorer

It's not that highlighting stops after 20 lines, in my case there are comment lines after line 20, when I remove the line on 20 the rest works fine. Syntax auto fill also stops working in my example I just noted. I tried it at home where I use 9.0 with no problem at all. I'll just wait for a new version @ the office.  I'll accept your answer for now.

0 Karma

Hoekb03
Explorer

My query doesn't do the trick btw, still curious about the cause of the highlighting not working.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...