Dashboards & Visualizations

Why does chart overlay on not like colons in chrome?

| makeresults | eval value=1 | stats count as "count: 1", count by value

If you try to use chart overlay with "count: 1" using the above query, nothing happens.  It doesn't apply the overlay.  If you try with "count", it works as expected.  Both have worked in the past.  Is this fixed in a future version?  I didn't see it on the known issues page.  Thanks.


Labels (1)


Gah, thank you for posting this, I was second guessing myself.  I'm running into the same issue, not realizing it was the colons. 

This is not browser-specific:  I can repo in Safari and Firefox as well.

If I may tweak your repo into something that Splunk causes:


| makeresults | eval value=1 | timechart fixedrange=false max(value) as max, count by value


Chart overlay will not work with the timechart result because Splunk creates the fields "count: 1" and "max: 1".

Workaround: rename all the fields without the colon:


| rename "count: 1" as count_1, "max: 1" as max_1


Now you can put either field into the overlay.  This doesn't scale with lots of data though.

My Splunk:

Splunk Enterprise
Build: ae6821b7c64b

Tags (1)
0 Karma


It is actually the spaces, not the colons.  It works on newer versions of splunk if you can update.

The only other workaround I'm aware of is using the Trellis view.


Ah, thanks for the update. I'm glad its been addressed. I read thru all the subsequent Release Notes 8.2.4-9.0 and didn't spot it. 

I'll get a support ticket submited to track down which version specifically fixes it.

Thank you!



0 Karma
Get Updates on the Splunk Community!

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...