<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom text - Table in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694103#M56836</link>
    <description>&lt;LI-CODE lang="markup"&gt;index=testindex source=application.logs
|rex "ErrorCode\:\[?&amp;lt;Error_Code&amp;gt;\d+]"
|search Error_Code IN(200, 500, 400, 505, 500)
|stats count by Error_Code
|Where count &amp;gt; 5&lt;/LI-CODE&gt;&lt;P&gt;output:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Error_Code&lt;/TD&gt;&lt;TD width="50%"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;200&lt;/TD&gt;&lt;TD width="50%"&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;500&lt;/TD&gt;&lt;TD width="50%"&gt;100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;400&lt;/TD&gt;&lt;TD width="50%"&gt;40&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;505&lt;/TD&gt;&lt;TD width="50%"&gt;45&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;500&lt;/TD&gt;&lt;TD width="50%"&gt;32&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;Instead of Errorcodes we want to display a custom text&amp;nbsp; as shown below.&lt;BR /&gt;How can we do this??&lt;/P&gt;&lt;P&gt;Expected output:&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Error_Code&lt;/TD&gt;&lt;TD width="50%"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 200&lt;/TD&gt;&lt;TD width="50%"&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 500&lt;/TD&gt;&lt;TD width="50%"&gt;100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 400&lt;/TD&gt;&lt;TD width="50%"&gt;40&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 505&lt;/TD&gt;&lt;TD width="50%"&gt;45&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 500&lt;/TD&gt;&lt;TD width="50%"&gt;32&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jul 2024 20:16:18 GMT</pubDate>
    <dc:creator>mahesh27</dc:creator>
    <dc:date>2024-07-23T20:16:18Z</dc:date>
    <item>
      <title>Custom text - Table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694103#M56836</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=testindex source=application.logs
|rex "ErrorCode\:\[?&amp;lt;Error_Code&amp;gt;\d+]"
|search Error_Code IN(200, 500, 400, 505, 500)
|stats count by Error_Code
|Where count &amp;gt; 5&lt;/LI-CODE&gt;&lt;P&gt;output:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Error_Code&lt;/TD&gt;&lt;TD width="50%"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;200&lt;/TD&gt;&lt;TD width="50%"&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;500&lt;/TD&gt;&lt;TD width="50%"&gt;100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;400&lt;/TD&gt;&lt;TD width="50%"&gt;40&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;505&lt;/TD&gt;&lt;TD width="50%"&gt;45&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;500&lt;/TD&gt;&lt;TD width="50%"&gt;32&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;Instead of Errorcodes we want to display a custom text&amp;nbsp; as shown below.&lt;BR /&gt;How can we do this??&lt;/P&gt;&lt;P&gt;Expected output:&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Error_Code&lt;/TD&gt;&lt;TD width="50%"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 200&lt;/TD&gt;&lt;TD width="50%"&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 500&lt;/TD&gt;&lt;TD width="50%"&gt;100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 400&lt;/TD&gt;&lt;TD width="50%"&gt;40&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 505&lt;/TD&gt;&lt;TD width="50%"&gt;45&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application received with errorcode 500&lt;/TD&gt;&lt;TD width="50%"&gt;32&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 20:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694103#M56836</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2024-07-23T20:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Custom text - Table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694108#M56837</link>
      <description>&lt;P&gt;Use the &lt;FONT face="courier new,courier"&gt;eval&lt;/FONT&gt; command to replace the Error_Code value with the desired text.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=testindex source=application.logs
| rex "ErrorCode\:\[?&amp;lt;Error_Code&amp;gt;\d+]"
| search Error_Code IN (200, 500, 400, 505)
| stats count by Error_Code
| eval Error_Code = "Application received with errorcode " + Error_Code
| where count &amp;gt; 5&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 20:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694108#M56837</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-23T20:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Custom text - Table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694109#M56838</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, Even i tried with eval command but it did not work.&lt;BR /&gt;But i tried as per&amp;nbsp; your query it worked, thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 21:08:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694109#M56838</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2024-07-23T21:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Custom text - Table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694192#M56844</link>
      <description>&lt;P&gt;I don't understand the reply.&amp;nbsp; Did my answer work or not?&amp;nbsp; If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 12:16:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Custom-text-Table/m-p/694192#M56844</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-24T12:16:37Z</dc:date>
    </item>
  </channel>
</rss>

