Search Reference

 


iconify

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

iconify

Synopsis

Causes the ui to make a unique icon for each value of the fields listed.

Syntax

iconify field-list

Arguments

field-list
Syntax: <field>...
Description: The list of fields to display as a unique icon.

Description

Examples

Example 1: Displays an different icon for each process id.

... | iconify pid

Example 2: Displays an different icon for url and ip combination.

... | iconify url ip

Example 3: Displays an different icon for each eventtype.

... | iconify eventtype


See also

highlight

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.