Sorry to bump old post. Solution suggested by @niketnlay has solved it. Splunk Enterprise 8.0.5. This is the key concept: <table><format><colorPalette type="expression"> I had no luck with simply putting a token into the code the UI is generating for us: <colorPalette type="list"><scale type="threshold"> Below example works. <table>
...
<format type="color" field="age_in_mins">
<colorPalette type="expression">if(value >=
$threshold_in_mins_tok$,"#DC4E41", "#53A051")</colorPalette>
<!--colorPalette type="list">[#53A051,#DC4E41]</colorPalette>
<scale type="threshold">$threshold_in_mins_tok2$</scale-->
</format>
</table>
... View more