- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
While doing a basic raw search, I came across something I've never seen in Splunk -- the information column is turning red for certain logs before working with the data at all.
The only significant things about the logs that have the red highlighting is that they have an "error" tag, which I'm assuming is the reason why this is happening. I just didn't know highlighting logs before in the raw format was even possible.
If anyone has any idea what's causing this, or how to replicate this, I would be very interested.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

These are known as event type renderers and it’s coloring events based on their eventtype.
You can configure them via UI or via conf file
https://answers.splunk.com/answers/492197/how-to-enable-event-type-coloring.html
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

These are known as event type renderers and it’s coloring events based on their eventtype.
You can configure them via UI or via conf file
https://answers.splunk.com/answers/492197/how-to-enable-event-type-coloring.html
