Color themes

You can change the appearance of your search criteria by specifying a color theme. There are several themes to choose from.

Theme name Description
Default system themeInherits the default system theme.
LightWhite background. Black text. Colors for commands, arguments, functions, keyword modifiers, and Boolean operators.
DarkBlack background. Light grey text. Colors for commands, arguments, functions, keyword modifiers, and Boolean operators.

Color codes

The color coding that is used for the search syntax depends on the color theme that is implemented. The color codes for the Light and Dark themes are described in the following table.

Syntax component Color Example
CommandsBlue... | timechart
Command arguments Green... | timechart usenull=false
Functions Pink... | timechart count
Keyword modifiers and Boolean operators Orange... | timechart count BY productName
Inline comments Gray... | timechart count '''Plots the count of results over the last 24 hours'''

The following image shows syntax highlighting with the Dark theme.

This screen image shows the Dark color theme in the Search bar. The Dark theme is a black background with white text. The commands, arguments, functions, and keywords are in different colors.

Change the color theme

You change the color theme in the Search bar by using the account menu. You cannot change the color theme if you have a Splunk Free license. See About Splunk Free in the Admin manual.

  1. On the Splunk bar, select [User_account_name] > Preferences.
  2. Click SPL Editor.
  3. Confirm that Advanced editor is turned on.
  4. On the Themes tab, select the color theme that you want to use.
  5. Click Apply.