Dashboards & Visualizations

colorpallette expression not matching field value

thaghost99
Path Finder

hi, need some help, i have this format type but it seems the word 'up' is not matching for whatever reason.

there is no spaces or anything in the field value. 

the field value is extracted using 'rex'.

i have this working in other fields, but this one got me stuck. 

any help will be appreciated. 

 

<format type="color" field="state">
<colorPalette type="expression">if (value == "up","#Green", "#Yellow")</colorPalette>
</format>

 

thaghost99_0-1709222707938.png

 

Labels (3)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

I don't believe you can use colour names, such as Green and Yellow, you have to use hex codes or RGB, see here

https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/TableFormatsXML#Color_palette_types_and...

in your case it's interesting that you have yellow, as I would expect black if it does not understand colour names.

Have you tried

<colorPalette type="expression">if(value == "up","#00FF00", "#FFFF00")</colorPalette>

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

I don't believe you can use colour names, such as Green and Yellow, you have to use hex codes or RGB, see here

https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/TableFormatsXML#Color_palette_types_and...

in your case it's interesting that you have yellow, as I would expect black if it does not understand colour names.

Have you tried

<colorPalette type="expression">if(value == "up","#00FF00", "#FFFF00")</colorPalette>

Richfez
SplunkTrust
SplunkTrust

What's the actual regex you are using to capture it?
And if you are sure you are using the right syntax because you copy pasted it from some working one - you could try to add | eval state = "up" as the last command in the search to force it to be "up" and see if that works.  If it doesn't, then I'd say there's something else wrong with that syntax.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...