Splunk Search

Why SPL syntax highlighting not working correctly?

Hoekb03
Explorer

Hi,

I've created this rather complicated piece of SPL. To make it a bit more understandable I added some comment lines. In the screenshot you can see the SPL syntax highlighting stops working correctly from line #20. The strange thing is that when I remove line 20 all together it works fine, and there are more comment lines further on. Whatever comment I put on that position causes this behaviour. 

Hoekb03_2-1658741735482.png

Line removed, it works fine:

Hoekb03_3-1658742001878.png

Comment ```test comment``` breaks the thing down again. 

Hoekb03_4-1658742080743.png

It's just a minor cosmetic thing, but I'd like to know what's happening here and why. We're using splunk Enterprise 8.1.10.1 on my site. Any thoughts appreciated!

 

 

 

 

 

 

Labels (1)
Tags (2)
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @Hoekb03 ... I am using Splunk 8.2.5 and its SPL highlighting working fine even after 20 lines. Are you using older versions ah?!?!

Splunk 8.2.5.png

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Hoekb03 ... I am using Splunk 8.2.5 and its SPL highlighting working fine even after 20 lines. Are you using older versions ah?!?!

Splunk 8.2.5.png

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (1)
0 Karma

Hoekb03
Explorer

It's not that highlighting stops after 20 lines, in my case there are comment lines after line 20, when I remove the line on 20 the rest works fine. Syntax auto fill also stops working in my example I just noted. I tried it at home where I use 9.0 with no problem at all. I'll just wait for a new version @ the office.  I'll accept your answer for now.

0 Karma

Hoekb03
Explorer

My query doesn't do the trick btw, still curious about the cause of the highlighting not working.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...