Dashboards & Visualizations

Change Cluster Map Color to solid color with error

nwoodco1
Explorer

Hello, I am trying to make it so that my cluster map pie chart turns all one color when there is an event containing an error. So instead of being mostly green with a little bit of red, I would like the whole pie to turn red. Thanks!

0 Karma

efavreau
Motivator

Are you changing the values if there's an error? Because you could end your search with an eval if errors >0, events=errors, which could turn it all red (let's say errors is red and non-errors is green). But then your green wouldn't show at all. Yyou probably wouldn't want to do that though. You could turn the background white or red based on an eval for errors and adjusting the CSS. The easiest route might be to add a status indicator panel next to it, showing only the icon, and it evaluates if errors >0.

###

If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...