<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change colour of column based on variable/token in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498175#M138776</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard theme="light"&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
           | makeresults 
| eval field1=100,field2=200 
| append 
    [| makeresults 
    | eval field1=12, field2=5000] 
| append 
    [| makeresults 
    | eval field1=200, field2=100] 
| append 
    [| makeresults 
    | eval field1=9999, field2=2] 
| append 
    [| makeresults 
    | eval field1=12, field2=5000] 

           &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$latest$&amp;lt;/latest&amp;gt;
          &amp;lt;done&amp;gt;
            &amp;lt;set token="tokStatus"&amp;gt;$result.field1$&amp;lt;/set&amp;gt;
          &amp;lt;/done&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="color" field="field1"&amp;gt;
          &amp;lt;colorPalette type="expression"&amp;gt;if(value &amp;amp;gt; $tokStatus$, "#DC4E41", "#53A051")&amp;lt;/colorPalette&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 20 Mar 2020 06:26:14 GMT</pubDate>
    <dc:creator>vnravikumar</dc:creator>
    <dc:date>2020-03-20T06:26:14Z</dc:date>
    <item>
      <title>Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498172#M138773</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a table with 2 columns and I want to change the colour of one of them based on whether or not its bigger or smaller than the second column.&lt;BR /&gt;
For example, in the table below, I would expect the first 2 rows of column1 to be green, while the last 2 rows will be red: &lt;/P&gt;

&lt;P&gt;field1, field2&lt;BR /&gt;
100, 200&lt;BR /&gt;
12, 5000&lt;BR /&gt;
200, 100&lt;BR /&gt;
9999, 2&lt;/P&gt;

&lt;P&gt;I've taken 2 approaches, configuring colorPalette with a variable from my search directly which seemed to not work, secondly tried to update a token through the search because one of the links below suggests that tokens will work.&lt;/P&gt;

&lt;P&gt;I've used these posts as references to no avail still:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/656201/can-i-use-if-match-x-regex-y-z-in-a-colorpalette-e.html"&gt;https://answers.splunk.com/answers/656201/can-i-use-if-match-x-regex-y-z-in-a-colorpalette-e.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/469742/how-to-edit-dashboard-to-use-token-values-to-deter.html"&gt;https://answers.splunk.com/answers/469742/how-to-edit-dashboard-to-use-token-values-to-deter.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/673787/how-to-set-a-token-based-on-search-results.html"&gt;https://answers.splunk.com/answers/673787/how-to-set-a-token-based-on-search-results.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here's my sample dashboard:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Random title&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
           index=someIndex source=someSource| eval field1=bla, field2=bla | table field1 field2
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$latest$&amp;lt;/latest&amp;gt;
          &amp;lt;done&amp;gt;
            &amp;lt;set token="tokStatus"&amp;gt;$result.field1$&amp;lt;/set&amp;gt;
           &amp;lt;/done&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="color" field="latency"&amp;gt;
          &amp;lt;colorPalette type="expression"&amp;gt;if(value &amp;gt; $tokStatus$, "#53A051", "#DC4E41")&amp;lt;/colorPalette&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas on how to do so?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 05:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498172#M138773</guid>
      <dc:creator>jimmyting93</dc:creator>
      <dc:date>2020-03-20T05:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498173#M138774</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Check the below link and modify js accordingly&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/661894/how-to-color-cell-contents-with-css-and-js.html#answer-661940"&gt;https://answers.splunk.com/answers/661894/how-to-color-cell-contents-with-css-and-js.html#answer-661940&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 06:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498173#M138774</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2020-03-20T06:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498174#M138775</link>
      <description>&lt;P&gt;Is there a way without js?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 06:04:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498174#M138775</guid>
      <dc:creator>jimmyting93</dc:creator>
      <dc:date>2020-03-20T06:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498175#M138776</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard theme="light"&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
           | makeresults 
| eval field1=100,field2=200 
| append 
    [| makeresults 
    | eval field1=12, field2=5000] 
| append 
    [| makeresults 
    | eval field1=200, field2=100] 
| append 
    [| makeresults 
    | eval field1=9999, field2=2] 
| append 
    [| makeresults 
    | eval field1=12, field2=5000] 

           &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$latest$&amp;lt;/latest&amp;gt;
          &amp;lt;done&amp;gt;
            &amp;lt;set token="tokStatus"&amp;gt;$result.field1$&amp;lt;/set&amp;gt;
          &amp;lt;/done&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="color" field="field1"&amp;gt;
          &amp;lt;colorPalette type="expression"&amp;gt;if(value &amp;amp;gt; $tokStatus$, "#DC4E41", "#53A051")&amp;lt;/colorPalette&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Mar 2020 06:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498175#M138776</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2020-03-20T06:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498176#M138777</link>
      <description>&lt;P&gt;&lt;IMG src="https://ibb.co/C1kLXVF" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://ibb.co/C1kLXVF"&gt;https://ibb.co/C1kLXVF&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Sorry for crappy photo, couldnt take screenshot... The example doesnt work? It only makes the whole panel green?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 00:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498176#M138777</guid>
      <dc:creator>jimmyting93</dc:creator>
      <dc:date>2020-03-25T00:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498177#M138778</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'll give you the answer&lt;BR /&gt;
I'm going to use SPL first.&lt;/P&gt;

&lt;P&gt;In the query, the two fields are compared by using the eval command, and if the small field is 1 and the large field is 2, 3 is displayed&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 07:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498177#M138778</guid>
      <dc:creator>jinseong</dc:creator>
      <dc:date>2020-03-25T07:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498178#M138779</link>
      <description>&lt;P&gt;I dont understand your answer? Can you provide a sample?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 22:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498178#M138779</guid>
      <dc:creator>jimmyting93</dc:creator>
      <dc:date>2020-03-25T22:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Change colour of column based on variable/token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498179#M138780</link>
      <description>&lt;P&gt;I checked I'm getting color as per the condition&lt;/P&gt;

&lt;P&gt;&lt;A href="https://ibb.co/C5DRpnR"&gt;https://ibb.co/C5DRpnR&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 16:23:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Change-colour-of-column-based-on-variable-token/m-p/498179#M138780</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2020-03-27T16:23:26Z</dc:date>
    </item>
  </channel>
</rss>

