Splunk Enterprise

How to color the field value based on the value present in another field?

Ashwini008
Builder

Hi,

I want to color the filename value (.i.e Account) with red color , if the value present in another fields is blank. How can i do? preferably  using xml code....

filename

application

ID

Status

Account

 

 

 

Account1

spear

Ydg123

p

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

See my answer here  Essentially, you make the field you want to colour a multi-value field with a value that you configure to be mapped to the colour you want, then you hide (display: none;) the additional value.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...