Dashboards & Visualizations

Column formating Splunk studio

Aresndiz
Explorer

Does anyone know if it is possible to create specific thresholds for each host in the dashboard studio table? I'm using a table where I focus on hard disk usage, previously I had no problems with the configuration since the threshold was 80% amber and 90% red. However, I was asked to adjust this threshold to 90 amber and 95 red only for a specific server. My question is, is it possible for the color format table to have different thresholds depending on the host?

Aresndiz_0-1738265447357.png

Aresndiz_1-1738265644751.png

 

 

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

You can do this by overwriting some of the options within the table source:
Have a look at the following example:

Xnip2025-01-30_23-35-50.png

You can see that the colour is specified using SPL instead of logic within the Dashboard editor. Using a field prefixed with underscore _ will stop it showing in the table.
Then update the options for the table and add/edit the columnFormat:

        "columnFormat": {
            "<YourHighlightedField>": {
                "rowBackgroundColors": "> table | seriesByName('_colour')"
            }
        }

 

Xnip2025-01-30_23-36-34.png


I hope this helps!

View solution in original post

0 Karma

livehybrid
SplunkTrust
SplunkTrust

You can do this by overwriting some of the options within the table source:
Have a look at the following example:

Xnip2025-01-30_23-35-50.png

You can see that the colour is specified using SPL instead of logic within the Dashboard editor. Using a field prefixed with underscore _ will stop it showing in the table.
Then update the options for the table and add/edit the columnFormat:

        "columnFormat": {
            "<YourHighlightedField>": {
                "rowBackgroundColors": "> table | seriesByName('_colour')"
            }
        }

 

Xnip2025-01-30_23-36-34.png


I hope this helps!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...