Dashboards & Visualizations

How can I control a Radial Guage's range values with result values?

ScottSusman
Explorer

I would like to see if something (ie, number of transactions/hour) is within an expected range. I have a search that returns a single row with the fields Recent, High, Low.
I am trying to visualize this with a Radial Gauge, but am having trouble getting the range values set correctly.

  <chart>
    <search>
      <query>... | fields Recent, High, Low</query>
      <done>
        <set token="lowThreshold">$result.Low$</set>
        <set token="highThreshold">($result.High$</set>
        <set token="max">eval(round(result.High$ * 1.2), 0)</set>
      </done>
    </search>
    <option name="charting.chart">radialGauge</option>
    <option name="charting.chart.style">minimal</option>
    <option name="charting.chart.rangeValues">[0,$lowThreshold$,$highThreshold$,$max$]</option>
    <option name="charting.gaugeColors">["0xBF3030","0x7e9f44","0xBF3030"]</option>
  </chart>

This keeps ignoring the token settings and using the defaults of 0, 30, 70, 100. What do I need to change to use my ranges instead of the default ones?

Thank you!

0 Karma
1 Solution

sundareshr
Legend

Try this in your query...

<query>... | gauge Recent, Low, High</query>

View solution in original post

0 Karma

casties
New Member

Hi,

just a short note here:

did you recognize the extra "(" in ($result.High$ in line 6?

0 Karma

sundareshr
Legend

Try this in your query...

<query>... | gauge Recent, Low, High</query>
0 Karma

ScottSusman
Explorer

That changed my result from Recent, High, Low to x, y1, y2 but the gauge looks the same.
Interestingly, the gauge first displayed it looked (almost) right...for a second. And then flashed back to the defaults.

0 Karma

somesoni2
Revered Legend

If you're setting the gauge in the search itself, get rid of charting.chart.rangeValues.

ScottSusman
Explorer

Huzzah! That works! Thank you!

0 Karma

ScottSusman
Explorer
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...