Dashboards & Visualizations

Is there any easy way to keep the colors for the same SQL statements/hashes between the two panels?

damucka
Builder

Hello,

We have several cases, where we relate the data between panels. On the example screenshots below, we have:

1/ Chart with the number of database threads in time, and the sum of threads per time unit involved in the execution of the particular SQL statement (SQL hash) - represented by the different colors: 

damucka_0-1647866824639.png

 

2/ Pie chart showing the portion of the particular SQL statement / hash in the given time span:

damucka_1-1647866847390.png

Is there any easy way to keep the colors for the same SQL statements/hashes between the two panels?

Kind Regards, Kamil

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Apply some sort of sort so that the series (names) are in the same order.

View solution in original post

0 Karma

damucka
Builder

Unfortunately even after sorting both the same order, see the screenshot below, the colors assigned to both panels are different:

damucka_0-1647870229728.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

That's because they aren't sorted in the same order (you can see that from the legends) - how have you done the sorting?

0 Karma

damucka
Builder

You are right of course.

I managed to match it, but now the issue is, that the stacked column chart displays like 9 different SQL hashes + others and the pie chart way more of them + others. The not quite nice consequence is, that the color for "others" does not match.

Would you know a chart option for both, stacked column and pie chart to restrict the number of displayed values say to 7 + "others"?

I could not find it in the visualization options, so I guess this is some more advanced parameter I would use in the xml.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Probably the way to do this is to implement the "other" stat as part of the SPL, that way you have control - so long as it was under the number of series supported by the pie chart.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Apply some sort of sort so that the series (names) are in the same order.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...