Dashboards & Visualizations

Event type colors not shown in Dashboards

cemiam
Path Finder

I have created an event type and set a color for it. Events colored in search app and reports however they are not shown in the Dashboards. I have save it as both Inline Search and Report however issue is still the same. Do you have any suggestion to colorized Dashboard Panels?

Best Regards,
Cem

Tags (1)
0 Karma
1 Solution

cmerriman
Super Champion

add |fields eventtype to the end your search in the dashboard

View solution in original post

cmerriman
Super Champion

add |fields eventtype to the end your search in the dashboard

cemiam
Path Finder

Hi,

Soon I can see the colored events 🙂 Thanks for your assitance.

All the best,
Cem

0 Karma

cemiam
Path Finder

I am trying coloring dashboards panel using eventtypes like in the article below.

http://docs.splunk.com/Documentation/Splunk/6.5.1/Knowledge/Defineeventtypes

I have added the screenshots. As you can see events are colored in the search app and reports. However it is not worked with Dashboard Panels.

Dashboard: http://imgur.com/a/iJuCS
Report: http://imgur.com/a/Q2jKa
Search Events: http://imgur.com/a/osQSV

Best Regards,
Cem

0 Karma

cmerriman
Super Champion

can you share some syntax of what you're displaying in the dashboard? coloring eventtypes i believe only shows when viewing raw events. If you just want to highlight certain text, in 6.5, you can use table formatting to highlight values.

http://docs.splunk.com/Documentation/Splunk/6.5.1/Knowledge/Defineeventtypes
http://docs.splunk.com/Documentation/Splunk/6.5.1/Viz/TableFormatsFormatting#Column_color

0 Karma

cemiam
Path Finder

I am trying coloring dashboards panel using eventtypes like in the article below.

http://docs.splunk.com/Documentation/Splunk/6.5.1/Knowledge/Defineeventtypes

I have added the screenshots. As you can see events are colored in the search app and reports. However it is not worked with Dashboard Panels.

Dashboard: http://imgur.com/a/iJuCS
Report: http://imgur.com/a/Q2jKa
Search Events: http://imgur.com/a/osQSV

Best Regards,
Cem

0 Karma

maffreitas
Path Finder

Let me know if you talking about this:

http://docs.splunk.com/Documentation/Splunk/6.5.2/Viz/BuildandeditdashboardswithSimplifiedXML#Specif...

If not, please share with us more details or some code/images.

Regards.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...