<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard panel features in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623163#M14690</link>
    <description>&lt;P&gt;2. for the multi series colours : Please tell me what i should add so that i can get the different colours.&lt;BR /&gt;Here i am calculating the avg response time by host and code_desc.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i am using the below query :&lt;BR /&gt;index=xxxxx code_desc=NH23FG OR code_desc=TH45GH source=xxxx*&lt;BR /&gt;|stats avg(responsetime) as Avg_response by host, code_desc&lt;BR /&gt;|sort by Avg_response&lt;BR /&gt;|where Avg_response&amp;gt;500&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ash1_1-1670209069364.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22844i10E1F15767C03F0A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ash1_1-1670209069364.png" alt="Ash1_1-1670209069364.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;3. i have rounded up the value upto 2 decimal places, now it is showing correctly, but if i want to show complete number upto 13 .&lt;BR /&gt;how can i do that??&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 03:02:09 GMT</pubDate>
    <dc:creator>Ash1</dc:creator>
    <dc:date>2022-12-05T03:02:09Z</dc:date>
    <item>
      <title>Help with Dashboard panel features?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623088#M14676</link>
      <description>&lt;P&gt;I have a dashboard where I want to get the following features:&lt;BR /&gt;&lt;BR /&gt;1. Drill down option i mentioned to "Link to search" but when i am clicking on the graph it is the search page is opening in same tab, but i want to open that in another tab.&lt;BR /&gt;2. I have another panel where the bar graph is showing by hosts, so i want to show up different colors for each host, how can i do this.&lt;/P&gt;
&lt;P&gt;3. i want to display the values on the graph, it is displaying but it is overlapping, how can make them display clearly.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 12:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623088#M14676</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2022-12-05T12:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623090#M14677</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Hi&lt;BR /&gt;&lt;BR /&gt;please find following repponses&lt;BR /&gt;&lt;SPAN&gt;&lt;STRONG&gt;1. Drill down option i mentioned to "Link to search" but when i am clicking on the graph it is the search page is opening in same tab, but i want to open that in another tab.&lt;BR /&gt;&lt;BR /&gt;in dashboard panel seetins you can check option open in tab , then your drilldown open in new tab&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;STRONG&gt;2. I have another panel where the bar graph is showing by hosts, so i want to show up different colors for each host, how can i do this.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;you can use follwing option to give cutsom colors&lt;BR /&gt;&lt;BR /&gt;&amp;lt;option name="charting.fieldColors"&amp;gt;{"count": #66FF00}&amp;lt;/option&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartConfigurationReference?_ga=2.144048631.352213148.1669520590-1425316371.1663822340#General_chart_properties" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartConfigurationReference?_ga=2.144048631.352213148.1669520590-1425316371.1663822340#General_chart_properties&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;3. i want to display the values on the graph, it is displaying but it is overlapping, how can make them display clearly.&lt;BR /&gt;&lt;BR /&gt;Can you share the screenshot to check furthur&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SanjayReddy_0-1670043741546.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22831i75F9AC16D1F92BF4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SanjayReddy_0-1670043741546.png" alt="SanjayReddy_0-1670043741546.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 05:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623090#M14677</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-12-03T05:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623105#M14681</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy , thank you for replying .&lt;BR /&gt;&lt;BR /&gt;1. now its working as expected-Drill down option in new tab.&lt;/a&gt;&lt;/P&gt;&lt;P&gt;2.&lt;STRONG&gt;&lt;SPAN&gt; I have another panel where the bar graph is showing by hosts, so i want to show up different colors for each host, how can i do this&lt;BR /&gt;&lt;BR /&gt;For this my query is: index=asdf sourcetype=ghtfg |stats count by host.&lt;BR /&gt;So my dashboard panel is displaying with multiple hosts as bar graph.&lt;BR /&gt;here i want to show each single host in different colours.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;For example: in the dashboard panel if it is dsiplaying 4 hosts&lt;BR /&gt;1st host should display as red, 2nd host should display as green so on....&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ash1_0-1670082196449.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22834iED76146235AE71AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ash1_0-1670082196449.png" alt="Ash1_0-1670082196449.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3.&lt;SPAN&gt;. i want to display the values on the graph, it is displaying but it is overlapping, how can make them display clearly.&lt;BR /&gt;if you see here all values are overlapping, i want this values should individually without overlapping.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ash1_1-1670082829010.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22835iC983DBDD0B3DF36A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ash1_1-1670082829010.png" alt="Ash1_1-1670082829010.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 15:55:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623105#M14681</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2022-12-03T15:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623143#M14687</link>
      <description>&lt;P&gt;If you are doing&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search...
| stats count by host&lt;/LI-CODE&gt;&lt;P&gt;then just add&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transpose 0 header_field=host column_name=Host&lt;/LI-CODE&gt;&lt;P&gt;but that graph example you posted is not a count by host.&lt;/P&gt;&lt;P&gt;If you have two fields then you can use the chart command to get multi-series&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search...
| chart count over X by Y&lt;/LI-CODE&gt;&lt;P&gt;where Y will by the multi series that is shown in different colours&lt;/P&gt;&lt;P&gt;As for your overlapping values, with your non-rounded values, where you are displaying 13 decimal places, you should round those values - do you really need all 13 places??&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval x=round(x,2)&lt;/LI-CODE&gt;&lt;P&gt;will round to 2dp&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2022 21:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623143#M14687</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-12-04T21:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623163#M14690</link>
      <description>&lt;P&gt;2. for the multi series colours : Please tell me what i should add so that i can get the different colours.&lt;BR /&gt;Here i am calculating the avg response time by host and code_desc.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i am using the below query :&lt;BR /&gt;index=xxxxx code_desc=NH23FG OR code_desc=TH45GH source=xxxx*&lt;BR /&gt;|stats avg(responsetime) as Avg_response by host, code_desc&lt;BR /&gt;|sort by Avg_response&lt;BR /&gt;|where Avg_response&amp;gt;500&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ash1_1-1670209069364.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22844i10E1F15767C03F0A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ash1_1-1670209069364.png" alt="Ash1_1-1670209069364.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;3. i have rounded up the value upto 2 decimal places, now it is showing correctly, but if i want to show complete number upto 13 .&lt;BR /&gt;how can i do that??&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 03:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623163#M14690</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2022-12-05T03:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623346#M14711</link>
      <description>&lt;P&gt;For multi series colour, use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| chart avg(responsetime) as Avg_response over host by code_desc&lt;/LI-CODE&gt;&lt;P&gt;rather than stats&lt;/P&gt;&lt;P&gt;If you want to show 13 decimal places for all values on the chart, then it will look like the messy chart you have.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 23:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623346#M14711</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-12-05T23:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623354#M14713</link>
      <description>&lt;P&gt;when i am using chart no data is coming from the query.&lt;/P&gt;&lt;PRE&gt;| chart avg(responsetime) as Avg_response over host by code_desc&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;on e more point how can i mention the option name&lt;BR /&gt;&amp;lt;option name ="charting.fieldSeries"&amp;gt;{xxxxxxxxx}&amp;lt;/option&amp;gt;&lt;BR /&gt;please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 01:25:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623354#M14713</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2022-12-06T01:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel features</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623364#M14714</link>
      <description>&lt;P&gt;There will be no field Avg_response using chart, so you can put the chart line after your where clause&lt;/P&gt;&lt;P&gt;index=xxxxx code_desc=NH23FG OR code_desc=TH45GH source=xxxx*&lt;BR /&gt;| stats avg(responsetime) as Avg_response by host, code_desc&lt;BR /&gt;| where Avg_response&amp;gt;500&lt;BR /&gt;| sort by Avg_response&lt;BR /&gt;| chart values(Avg_response) as Avg_response over host by code_desc&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 07:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-with-Dashboard-panel-features/m-p/623364#M14714</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-12-06T07:09:45Z</dc:date>
    </item>
  </channel>
</rss>

