Dashboards & Visualizations

Help with same color between Chart and Event Annotation

Menzoc
New Member

Hello All,

I try to get the same colors for the graphics and for the annotations, without success.
The differences in syntax between categoryColors and fieldsColors escape me.

Could you please help me?

 

 

<search> 
<query>index=main sourcetype=Oracle_Database $multiselect_token$ $asa_token$ EIRP &gt;-20|chart latest(EIRP) by _time,EQUIP</query> 
</search> 
<search type="annotation"> 
<query>index=main sourcetype=Oracle_Database (IS_CAL AND $asa_token$ AND $antenna_code$ ) | eval annotation_label = Calibrate | eval annotation_category = EQUIP</query> 
</search> 
<option name="charting.annotation.categoryColors">{"#53a051","#0877a6","#f8be34","#f1813f","#dc4e41","#62b3b2","#294e70"}</option> 
<option name="charting.fieldColors">{53A051,0877A6,F8BE34,F1813F,DC4E41,62B3B2,294E70}</option> 

 

 

 

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...