Dashboards & Visualizations

Enhance Trellis chart with text from a lookup

jhuysing
Explorer

I have a search from which i produce a trellis of  the sum of various error codes from multiple machines 
I would like to enhance the charts  with a short description of text.
I  could  add the text to the code value  and create a new  value name  and do the split on the new  "codetext".
But, then I can't use the drill down  feature.

Is there another way to add some text to the individual graphs

Labels (3)
0 Karma

jhuysing
Explorer

I have been fiddling around trying to us a eval to strip the phrase from the passed  value

With no luck

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Not sure what you are trying to express.  This is what YOU come up with

| rex field=Error_Text".*:\s(?P<Code>\d{3})"
| lookup error_codes Code OUTPUT Phrase
| eval CodePhrase = Code+" -- "+Phrase

Does this add Phrase to your trellis label or not?  I bet this does.  If it does, what's wrong with this method? 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Why can't you use the drilldown feature?

0 Karma

jhuysing
Explorer

Sorry been busy with other work

Maybe I  am doing this wrong
The only way I could figure out how  give a bit more information in  a graph was  to  join the code  and phrase and then use that in the Split By in the Trellis

| rex field=Error_Text".*:\s(?P<Code>\d{3})"
| lookup error_codes Code OUTPUT Phrase
| eval CodePhrase = Code+" -- "+Phrase


When I use the Drill down it using joined  "codephrase"  field.

So I am wondering if there is another way to add the text  to  the graphs

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Is there anything wrong with the method you already use?  Or is there a specific effect this is not giving you?

If you think it through, trellis has only one single variable for breakdown and display.  All you can do is to change this value.  You search already does that.  If it ain't broken and disclaimers😃

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...