Splunk Dev

Getting rid of "other" in pie chart

Nicholas_Key
Splunk Employee
Splunk Employee

Splunk Ninjas,

It seems that I'm unable to remove "other" in my pie chart when I do this:

index=facebook sourcetype="facebook_stream_table" stream_attribution="*" | eval stream_attribution=if(stream_attribution=="", "None", stream_attribution) | chart count over stream_attribution useother=false

Also I'm seeing this message "The following options were specified but have no effect when a split-by clause is not provided:useother"

Then I tried

index=facebook sourcetype="facebook_stream_table" stream_attribution="*" | eval stream_attribution=if(stream_attribution=="", "None", stream_attribution) | chart count over stream_attribution limit=1000 useother=false

and I get this message "The following options were specified but have no effect when a split-by clause is not provided:limit, useother"

I'm unable to get any results when I drilldown with stream_attribution=other since there isn't such value in sourcetype=facebook_stream_table

I also took a look at this http://splunk-base.splunk.com/answers/30018/useotherf-in-a-pie-chart but it doesn't work.

Splunk version: 4.3.1, MacOSX

Tags (1)

jkat54
SplunkTrust
SplunkTrust

I edited the visualization to add this:

<option name="charting.chart.sliceCollapsingThreshold">0.01</option>

But i did so through the UI by clicking on the "paint brush" above the pie chart when in edit mode and setting the "minimum size" to 0%.

Doing that added the above to the dashboards xml.

0 Karma

notme_given
New Member

This will work (adapting to your indices, fields, etc)

index=linuxfirewall IN=eth3 PROTO=TCP | top DPT | chart count by DPT

The top command limits what you get and drops the 'other' aggregation.

0 Karma

MHibbin
Influencer

@Nicholas Key,

If you are using simple XML try removing the "useother" option and instead use

"sliceCollapsingThreshold" option

This helped me before, you can set it to zero, so it doesn't collapse the values into other.

http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomChartingConfig-chartlegend#piec...

Regards,

MHibbin

MHibbin
Influencer

OK cool, hopefully it works for you!

0 Karma

Nicholas_Key
Splunk Employee
Splunk Employee

Thanks, Matt! I'll try this out and let you know how it turns out.

0 Karma

MHibbin
Influencer

checking "..?showsource=1", the advanced XML looks like you should add...
<param name="suppressionList">
<item>charting.chart.sliceCollapsingThreshold</item>
<item>charting.chart</item>
</param>

after the viewstate adapter, and
<param name="charting.chart.sliceCollapsingThreshold">0</param>

as a param of the chart.

jujis008
Explorer

thank you very much! that's what am looking for. BTW what the difference between and \
\0\
working perfectly.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...