All Apps and Add-ons

Percentage of Field

hafizuddin
Path Finder

hi,

I'm used status indicator to show the current status of the field. I had notice when I click on the field it show the count and percentage for the event. How can I simulate the percentage at the field to status indicator dashboard since I had attention when the 100% of Up will turn to UP with green color, when the percent of Up 70% it turn to Warning with color orange and when Up show below 40% it turn to red and Down.

alt text

0 Karma
1 Solution

cmerriman
Super Champion

to mimic that data, just use index=indexName|top GroupStatusName and you'll get the GroupStatusName, count and percent. to color the table, you click on the little paintbrush by the column name and set the rules to look for. see the document below.
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Viz/TableFormatsFormatting#Format_table_colum...

View solution in original post

0 Karma

cmerriman
Super Champion

to mimic that data, just use index=indexName|top GroupStatusName and you'll get the GroupStatusName, count and percent. to color the table, you click on the little paintbrush by the column name and set the rules to look for. see the document below.
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Viz/TableFormatsFormatting#Format_table_colum...

0 Karma

hafizuddin
Path Finder

yeay I can make it...so how if I want just to mimic the percent only where the count table i hide

0 Karma

cmerriman
Super Champion

add |fields - count to the end of query.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...