Splunk Search

Why isn't table column formatting working for some rows in the following search?

ddelapasse
Explorer

Can anyone tell me why coloring on these true/false values is not working for all the rows?

alt text

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

The problem is that your fields are multi-valued. Add this to the end of your search and it should work fine:

| foreach streamMissing shouldBeRecording [ eval <<FIELD>> = mvdedup(<<FIELD>>) ]

View solution in original post

0 Karma

woodcock
Esteemed Legend

The problem is that your fields are multi-valued. Add this to the end of your search and it should work fine:

| foreach streamMissing shouldBeRecording [ eval <<FIELD>> = mvdedup(<<FIELD>>) ]
0 Karma

ddelapasse
Explorer

Worked perfectly. Thanks very much!

0 Karma

wagnerlucena
Explorer

Are you using table or stats command in your search ?
It is not working because there is 2 values in one unique row. I mean, the Splunk will only color the value if the value match exactly true or false, not False False or True True in same line. If you are using table commands to show the results, you will need to change to stats command.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...