Dashboards & Visualizations

Color cell by token from search

noa
Loves-to-Learn

Hey there. I have a dashboard with a search query:

Index=my index TestRunId="$RunId$" | dedup TestName | eval Status=case(Outcome==0, "Failed, Outcome==1, "Passed") | table TestName

I want to keep the Outcome per row in a token to enable coloring the test name with his outcome.

How can I do it? Or does there is a way to table both the TestName and the Outcome but not show the outcome, and color the row based the outcome value?

 

Thanks.

Labels (1)
0 Karma

to4kawa
Ultra Champion
0 Karma

to4kawa
Ultra Champion
0 Karma

noa
Loves-to-Learn

But I don't want to preview the outcome in my table, can I still do it with SimpleXml?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...