<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Colour in timechart in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523908#M35420</link>
    <description>&lt;P&gt;I am trying to create a timechart of errors with but is not working&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=xxx &amp;nbsp;AND source = xxxx AND (Error* OR Exception*) | timechart distinct_count(txnid) as errCount | eval RAG = case ( errCount &amp;gt; 200, “Red”, &amp;nbsp;errCount &amp;gt; 100 AND errCount &amp;lt;=200, “Amber” , 1==1, &amp;nbsp;“ Green”)&lt;/P&gt;&lt;P&gt;&amp;lt;option name=“charting.fieldcolors”&amp;gt;{“Red”: 0xD93F3C, “Amber”: 0xFF9933, “Green”: 0x009933}&amp;lt;/option&amp;gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Oct 2020 12:52:35 GMT</pubDate>
    <dc:creator>ARaman77</dc:creator>
    <dc:date>2020-10-09T12:52:35Z</dc:date>
    <item>
      <title>Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523908#M35420</link>
      <description>&lt;P&gt;I am trying to create a timechart of errors with but is not working&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=xxx &amp;nbsp;AND source = xxxx AND (Error* OR Exception*) | timechart distinct_count(txnid) as errCount | eval RAG = case ( errCount &amp;gt; 200, “Red”, &amp;nbsp;errCount &amp;gt; 100 AND errCount &amp;lt;=200, “Amber” , 1==1, &amp;nbsp;“ Green”)&lt;/P&gt;&lt;P&gt;&amp;lt;option name=“charting.fieldcolors”&amp;gt;{“Red”: 0xD93F3C, “Amber”: 0xFF9933, “Green”: 0x009933}&amp;lt;/option&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 12:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523908#M35420</guid>
      <dc:creator>ARaman77</dc:creator>
      <dc:date>2020-10-09T12:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523910#M35421</link>
      <description>&lt;P&gt;Try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;option name=“charting.fieldColors”&amp;gt;{“Red”: 0xD93F3C, “Amber”: 0xFF9933, “Green”: 0x009933}&amp;lt;/option&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 09 Oct 2020 12:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523910#M35421</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-09T12:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523919#M35422</link>
      <description>&lt;P&gt;Sorry its not working&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 13:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523919#M35422</guid>
      <dc:creator>ARaman77</dc:creator>
      <dc:date>2020-10-09T13:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523924#M35423</link>
      <description>&lt;P&gt;You haven't included RAG in your chart&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 13:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/523924#M35423</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-09T13:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524017#M35434</link>
      <description>&lt;P&gt;Can you let me know how to use it&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 06:43:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524017#M35434</guid>
      <dc:creator>ARaman77</dc:creator>
      <dc:date>2020-10-10T06:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524025#M35435</link>
      <description>&lt;P&gt;You can assign different colours to different series in the chart. In your case, you only have one series errCount so you could set the colour of that rather than letting splunk pick a colour for you.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 09:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524025#M35435</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-10T09:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524031#M35436</link>
      <description>&lt;P&gt;I want the colour of errCount to change depending on whether is greater 200, 100 or Less than 100&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 15:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524031#M35436</guid>
      <dc:creator>ARaman77</dc:creator>
      <dc:date>2020-10-10T15:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Colour in timechart</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524058#M35438</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227370"&gt;@ARaman77&lt;/a&gt;&amp;nbsp;just add the following two SPL pipes to your existing search. Current you have only one series with numerical data. So only one series color gets applied.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval {RAG}=errCount
| fields - RAG errCount&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 10:22:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Colour-in-timechart/m-p/524058#M35438</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2020-10-11T10:22:03Z</dc:date>
    </item>
  </channel>
</rss>

