<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Column Chart in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265792#M16758</link>
    <description>&lt;P&gt;After you';ve selected the chart overlay, add following to line to your dashboard xml of the chart.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;option name="charting.chart.showMarkers"&amp;gt;true&amp;lt;/option&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;....
&amp;lt;chart&amp;gt;
    &amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;eventtype=evt-rollover-summary earliest=-1d latest=@d 
 | stats latest(poolsz) as "PoolSize" sum(b) as "PoolUsage" by pool
 | rename pool AS "Pool Name"
 | eval "Pool Size (Gb)" = round(PoolSize/1024/1024,0)
 | eval "Pool Usage (Gb)" = round(PoolUsage/1024/1024,0) 
 | fields - PoolSize, PoolUsage
&amp;lt;/query&amp;gt;
....
..
&amp;lt;/search&amp;gt;
.....
        &amp;lt;option name="charting.chart.showMarkers"&amp;gt;true&amp;lt;/option&amp;gt;
......
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 31 Jan 2017 19:36:19 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2017-01-31T19:36:19Z</dc:date>
    <item>
      <title>Column Chart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265791#M16757</link>
      <description>&lt;P&gt;My search produces output containing 5 license pool names, their configured pool size, and the volume that was indexed at the time of the rollover. &lt;/P&gt;

&lt;P&gt;My search:&lt;BR /&gt;
eventtype=evt-rollover-summary earliest=-1d latest=@d &lt;BR /&gt;
  | stats latest(poolsz) as "PoolSize" sum(b) as "PoolUsage" by pool&lt;BR /&gt;
  | rename pool AS "Pool Name"&lt;BR /&gt;
  | eval "Pool Size (Gb)" = round(PoolSize/1024/1024,0)&lt;BR /&gt;
  | eval "Pool Usage (Gb)" = round(PoolUsage/1024/1024,0) &lt;BR /&gt;
  | fields - PoolSize, PoolUsage&lt;/P&gt;

&lt;P&gt;I'd like the column chart to just produce a 'dot' above the "Pool Usage (Gb)" column containing the "Pool Size (Gb)" field, but all I can seem to produce is a solid line for the overlay with nothing marking the line where the Pool Size Value is met.&lt;BR /&gt;
Not sure what I need to choose in the Overlay section to highlight the associated Pool Size value above the Pool Usage for a given Pool.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 19:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265791#M16757</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2017-01-31T19:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Column Chart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265792#M16758</link>
      <description>&lt;P&gt;After you';ve selected the chart overlay, add following to line to your dashboard xml of the chart.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;option name="charting.chart.showMarkers"&amp;gt;true&amp;lt;/option&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;....
&amp;lt;chart&amp;gt;
    &amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;eventtype=evt-rollover-summary earliest=-1d latest=@d 
 | stats latest(poolsz) as "PoolSize" sum(b) as "PoolUsage" by pool
 | rename pool AS "Pool Name"
 | eval "Pool Size (Gb)" = round(PoolSize/1024/1024,0)
 | eval "Pool Usage (Gb)" = round(PoolUsage/1024/1024,0) 
 | fields - PoolSize, PoolUsage
&amp;lt;/query&amp;gt;
....
..
&amp;lt;/search&amp;gt;
.....
        &amp;lt;option name="charting.chart.showMarkers"&amp;gt;true&amp;lt;/option&amp;gt;
......
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 31 Jan 2017 19:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265792#M16758</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-01-31T19:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Column Chart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265793#M16759</link>
      <description>&lt;P&gt;Thank you. Works perfectly.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 20:12:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Column-Chart/m-p/265793#M16759</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2017-01-31T20:12:07Z</dc:date>
    </item>
  </channel>
</rss>

