Dashboards & Visualizations

How to color Multivalued field in a dashboard xml?

Cheng2Ready
Path Finder

This is what I used
and after applying  the results just highlights the entire mv field in red

<format type="color">
<colorPalette type="expression"> case (match(value,"Large Effect"), "#ff0000",match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>
</format>

Cheng2Ready_0-1722976461481.png

looking for

Small effect -> Green
Medium effect -> Orange
and Large effect -> Red

Continuing from this search:
@ITWhisperer 
https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-csv-data-fields-message-data-into-fie...

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Too many brackets - try like this

<colorPalette type="expression">case (match(value,"Large Effect") OR match(value,"No"),"#ff0000",match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You will need to mvexpand the field for that you can colour rows of the field

0 Karma

Cheng2Ready
Path Finder

That worked!
but im trying to color the words " Large Effect " and "No"  to red
not sure what I did wrong here?

<colorPalette type="expression">case (match(value,"Large Effect") OR (match(value,"No"),"#ff0000",

match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Too many brackets - try like this

<colorPalette type="expression">case (match(value,"Large Effect") OR match(value,"No"),"#ff0000",match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...