Deployment Architecture

Why is search syntax highlighting not working in splunk 6.4.2 Enterprise edition?

samnathan
Explorer
  1. There is no "Account Settings>Preferences" under User Icon (Splunk Bar in 6.4.2)
  2. I have added "local" directory under $SPLUNK_HOME/etc/apps/search/
  3. Created file user-prefs.conf.spec.in (by copying user-prefs.conf under$SPLUNK_HOME/etc/apps/search/default)
  4. Opened the $SPLUNK_HOME/etc/apps/search/user-prefs.conf.spec.in/ and added the following: search_syntax_highlighting = true search_auto_format = false search_line_numbers = false
  5. Restarted the Splunk instance
  6. Search syntax highlighting doesn't work

Does this work only in higher versions? Please note it's not a free license version. Kindly help!

Tags (1)
0 Karma
1 Solution

jluo_splunk
Splunk Employee
Splunk Employee

Hi Samnathan,

Syntax highlighting was introduced in Splunk 6.6, which is why it won't work.

View solution in original post

0 Karma

jluo_splunk
Splunk Employee
Splunk Employee

Hi Samnathan,

Syntax highlighting was introduced in Splunk 6.6, which is why it won't work.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...