Dashboards & Visualizations

How to color Multivalued field in a dashboard xml?

Cheng2Ready
Path Finder

This is what I used
and after applying  the results just highlights the entire mv field in red

<format type="color">
<colorPalette type="expression"> case (match(value,"Large Effect"), "#ff0000",match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>
</format>

Cheng2Ready_0-1722976461481.png

looking for

Small effect -> Green
Medium effect -> Orange
and Large effect -> Red

Continuing from this search:
@ITWhisperer 
https://community.splunk.com/t5/Splunk-Search/How-to-extract-a-csv-data-fields-message-data-into-fie...

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Too many brackets - try like this

<colorPalette type="expression">case (match(value,"Large Effect") OR match(value,"No"),"#ff0000",match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You will need to mvexpand the field for that you can colour rows of the field

0 Karma

Cheng2Ready
Path Finder

That worked!
but im trying to color the words " Large Effect " and "No"  to red
not sure what I did wrong here?

<colorPalette type="expression">case (match(value,"Large Effect") OR (match(value,"No"),"#ff0000",

match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Too many brackets - try like this

<colorPalette type="expression">case (match(value,"Large Effect") OR match(value,"No"),"#ff0000",match(value,"Medium Effect"), "#ffff00",match(value,"Small Effect"),"#00ff00",true(),"#ffffff")</colorPalette>
0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 2)

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Index This | I am a number but I am countless. What am I?

January 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  Happy New Year! We’re ...

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

PLATFORM TECH TALKS What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience Thursday, February 27, ...