Alerting

How to define colors as per ranges using rangemap in geostats map.?

SanthoshSreshta
Contributor

Hi All.

I want alerts to be displayed on map for easy understanding.
i have used this Query

source="Churn_Map.csv" sourcetype="Churn_map" 
| eval Churn = if(Churn="True.","1","0") 
| eventstats sum(Churn) as true_churn , count(Churn) as total_churn by state 
| eval prop= true_churn*100 / total_churn 
| geostats values(prop) by StateName globallimit=0
| rangemap field=prop green=0-5 yellow=6-10 orange=11-15 default=red

but colors are not displaying as i defined. any improvements.?
the values are from min 5 to max 20. so i need alerts to seen on pie charts on map,by default it is showing some colors.
Green : 0-5
Yellow : 6-10
Orange :11-15
Red : 16 and above.
any reference documents and links are really appreciated 🙂

Thanks,
Santhosh.

0 Karma

jaracan
Communicator

Because the field "prop" is not existing anymore. You can add the "as" on your command to name it as prop again.

Something like this.
| geostats values(prop) as prop by StateName globallimit=0

0 Karma

vganjare
Builder
0 Karma

SanthoshSreshta
Contributor

I am not able to understand that @vganjare

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...