Can anyone tell me why coloring on these true/false values is not working for all the rows?
The problem is that your fields are multi-valued
. Add this to the end of your search and it should work fine:
| foreach streamMissing shouldBeRecording [ eval <<FIELD>> = mvdedup(<<FIELD>>) ]
The problem is that your fields are multi-valued
. Add this to the end of your search and it should work fine:
| foreach streamMissing shouldBeRecording [ eval <<FIELD>> = mvdedup(<<FIELD>>) ]
Worked perfectly. Thanks very much!
Are you using table or stats command in your search ?
It is not working because there is 2 values in one unique row. I mean, the Splunk will only color the value if the value match exactly true or false, not False False or True True in same line. If you are using table commands to show the results, you will need to change to stats command.