Knowledge Management

Does the latest version of Splunk support event type colors?

Cuyose
Builder

Latest splunk version does not support event type colors? It gives you the option to save the even type as a color, however this is never reflected in the search apps, these events are always black like any other event when returned in a search.

Tags (2)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

I hadn't tried it before, but I just did, and it worked, but only after I logged out and back in again. This is on Splunk Enterprise 6.1.4. The matching events display with a colored bar along the left, in the column marked with an i.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There is clearly some kind of bug here, since logging in and out shouldn't make a difference anyway. What version are you using?

0 Karma

Cuyose
Builder

I am on 6.1 Enterprise

0 Karma

ChrisG
Splunk Employee
Splunk Employee

6.1.0? 6.1.4 is the latest.

0 Karma

Cuyose
Builder

I'm on 6.1.2 apparently

0 Karma

Cuyose
Builder

Actually it looks like I am running
Splunk 6.1.2 (build 213098)

0 Karma

Cuyose
Builder

This doesn't work for me. No colored bars or text for the matched event types even though they are tagged with the event type i specified.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...