Dashboards & Visualizations

Change Single Value Visualization Based on Text

mistydennis
Communicator

Hello - I realize this question has been asked several times before and I've tried to implement every solution I've found, but nothing seems to be working.

I simply want to update a single value visualization based on the text. If "Yes", then green, and if "No", red. 

I've tried using older solutions involving rangemap and changing some of the charting options, but I'm not having any luck in v9.3.0. 

| inputlookup mylookup.csv 
| search $time_tok$ $field_tok$=Y 
| stats max(Distance) AS GuideMiles 
| appendcols 
    [| mylookup.csv 
    | search $month_tok$ 
    | stats max(TargetMiles)] 
| rename max(TargetMiles) AS TargetMiles 
| eval OnTarget=case(GuideMiles>=TargetMiles,"Yes", true(), "No") 
| table OnTarget

 

Labels (1)
0 Karma
1 Solution

LogUx
Motivator

@mistydennis 

### Steps to Use Single Value Visualization in your dashboard.

1. **Run the Query**: Use the query you provided to generate the `OnTarget` value.

2. **Select Visualization**:
- After running the query, go to the **Visualization** tab in the search results.
- From the available visualizations, choose **Single Value**.

3. **Configure Conditional Coloring**:
- Click on **Format** in the Visualization tab.
- Under **Color**, enable **Color by value**.
- Add your conditions:
- **If value is "Yes"**: Set the color to green.
- **If value is "No"**: Set the color to red.

4. **Save and Use**:
- Apply the settings, and you will see the value displayed either in green or red based on the result ("Yes" or "No").
- You can then save this as part of your dashboard if needed.

upvote is appreciated.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

While you have clearly shown your search (which by the way seems perfectly fine), what you haven't shown or described is what you have tried in your dashboard. Please can you provide further information?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...