Dashboards & Visualizations

field color change based on field value not working in dashboard

wangkevin1029
Communicator

Hi, Splunkers,

I have a field  duration in the panel, I added the following  <format></format> into the panel.

I want this duration field to show different color when it  is greater than 20.

but it doesn't work. 

<format type="color" field="duration">

          <colorPalette type="expression">if(tonumber(value)>20),"#789056")</colorPalette>

</format>

 

thx in advance.

 

Kevin

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

An if function requires 3 arguments if(condition, result if true, result if false) - you only have one, followed by a value outside the if function.

View solution in original post

wangkevin1029
Communicator

Hi, ITWhisperer

 

<colorPalette type="expression">if(tonumber(value)>20, "#789056","#009056")</colorPalette>

I put another color code here, it works.

However, here, I want to keep the original color , if   tonumber(value)>20  is false.

what value should I put here as color code for false?

 

besides, 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

An if function requires 3 arguments if(condition, result if true, result if false) - you only have one, followed by a value outside the if function.

wangkevin1029
Communicator

Hi, ITWhisperer,

 

it works when I just put a “” for false value, then it keeps original color.

<colorPalette type="expression">if(tonumber(value)>20, "#789056","")</colorPalette>

 

Kevin

 
0 Karma

wangkevin1029
Communicator

Btw, the original color in table is alternatively light/dark color every other line.

in this way, not sure how to specify the default color here.

 

Kevin

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...