Dashboards & Visualizations

Set a Default Color in Single Value Panel if Trendline is not displayed

Path Finder

I want to disable the varying red-green color indication by trend, and set it into a static color (green) if the trendline is not displaying at all in the panel. This happens when the timespan is less than the date range. For the example below, I only set it to three months, but when I set the date range into 2 years+, the sparkline will appear in the Sales (Yearly) panel.

The timespan of the single value chart has 1 year.

The query is:
| timechart span=1year sum(amount) as Sales

(the other panels have a span of 1 day, 1 week, and 1 month)

alt text
The Sales(Yearly) has no sparkline so I think it must have no red or green color indication. Is there a possible way to detect the appearance of the sparkline to trigger a token that will change the color of the panel?

alt text

0 Karma


@marxsabandana for the final Single Value panel you can disable the color directly from UI Edit, or through SimpleXML

<option name="useColors">0</option>

Is this what you are looking for?

| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Path Finder

Sorry, but actually what I really meant is to disable the varying red-green color indicators. Like, if a sparkline is not displayed below the single-value, the panel will be defaulted to color green.

0 Karma


Hi @marxsabandana Trendline won't show when the result has only 1 row. So you can maybe check result count on search:done event and set chart options accordingly?

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...