Splunk Search

Why is the information column turning red at search time?

rbechtold
Communicator

While doing a basic raw search, I came across something I've never seen in Splunk -- the information column is turning red for certain logs before working with the data at all.

The only significant things about the logs that have the red highlighting is that they have an "error" tag, which I'm assuming is the reason why this is happening. I just didn't know highlighting logs before in the raw format was even possible.

If anyone has any idea what's causing this, or how to replicate this, I would be very interested.

alt text

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

These are known as event type renderers and it’s coloring events based on their eventtype.

You can configure them via UI or via conf file

https://answers.splunk.com/answers/492197/how-to-enable-event-type-coloring.html

View solution in original post

jkat54
SplunkTrust
SplunkTrust

These are known as event type renderers and it’s coloring events based on their eventtype.

You can configure them via UI or via conf file

https://answers.splunk.com/answers/492197/how-to-enable-event-type-coloring.html

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...