I created 3 eventtypes, at creation I chose a different color for each one.
Everything worked fine, colors were displaying correctly as expected for each eventtype and for each tag I associated to the individual eventtypes. I tested this with several searches.
However, after logging out of Splunk and then back in the colors no longer displayed for any user. Permissions were set to global for all 3 eventtypes.
I tested it again by creating a new eventtype and the same thing happened.
I checked the eventtypes.conf and found the color wasn't set. I manually added each color to the eventtypes.conf in etc/app and restarted but no go, still no colors displaying.
I then moved the eventtypes.conf to system/local to see if that would work but again no luck.
Can't figure out why the colors aren't displaying, hopefully, someone can help with this.
↧