Splunk Search

what is colour code of boolean while using endswith?

Learner
Path Finder

Hi all, 

endswith=(notificationType="TestCompleted" OR notificationType="TestCancelled" OR notificationType="TestRejected" )

 this is my part of query.

when normally we use boolean like AND, OR they are in orange. but while using them with endswith, colour of booleans are grey.

so is it right, that colour of boolean is different? If not then how to correct that? 

Labels (1)
Tags (2)
0 Karma
1 Solution

diogofgm
SplunkTrust
SplunkTrust

That is a normal behaviour when you have those inside an atribute. They will work regardless. There are some cases the search does not colour the reserved words, commands etc.

------------
Hope I was able to help you. If so, some karma would be appreciated.

View solution in original post

diogofgm
SplunkTrust
SplunkTrust

That is a normal behaviour when you have those inside an atribute. They will work regardless. There are some cases the search does not colour the reserved words, commands etc.

------------
Hope I was able to help you. If so, some karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...