Dashboards & Visualizations

Horseshoe visualisation - Complex Logic

RobertEttinger8
Explorer

Hi,

I've been struggling with the horseshoe visualisation for a couple days. I have a specific scenario I would like to present but not sure if this can be done:

I have a table with 2 rows and 3 fields per row: source, count, status. Example:

source,count,status

sourceA,200,0(not breached)

sourceB,100,0(not breached)

sourceC, 100,1(breached)

I would like to show a horseshoe per source (trellis) where the dial shows the count but the color is based on the status. So, for instance, sources B and C would be similar looking (count-wise) but the color would be different as one is breached and the other one is not...

Is that possible? I've seen some posts about showing a different value as a token, but this doesn't work because 1-I need to work with multiple sources and 2-Each row may have its own threshold....

Thanks! 🙂

Labels (3)
Tags (3)
0 Karma

tscroggins
Champion

@RobertEttinger8 

Are you using the built-in radial gauge or the custom horseshoe meter?

The horseshoe meter trellis option splits by aggregation (column), so your results should include one event with one field per value:

| makeresults count=3
| streamstats count
| eval value=round(100*random()/2147483647)
| fields - _time
| transpose 0 header_field=count
| fields - column

RobertEttinger8_horseshoe.png

0 Karma

RobertEttinger8
Explorer

Hi,

 

I was talking about the horseshoe meter... 

 

The challenge comes when trying to apply different thresholds per horseshoe when using trellis and to display a value but the color of the threshold is based on another field... I actually found a visualization that allows this, the "Display Number Viz". It is a game changer for me 🙂

Thanks,

R

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...