Dashboards & Visualizations

help for changing the label of a pie chart

jip31
Motivator

hello
I use the stats below in order to display a pie chart with 2 labels

| stats count as NbHostHealthInf85 
| appendcols 
    [| inputlookup host.csv 
    | stats count as NbIndHost] 
| eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85) 
| eval NbHostHealthSup85=NbHostHealthSup85, NbHostHealthInf85=NbHostHealthInf85 
| table NbHostHealthSup85 NbHostHealthInf85 
| transpose

I need to replace NbHostHealthSup85 by >85% and NbHostHealthInf85 by <85%
What is the good way to do this because I m doing for example | stats count as "<85%" but it doesnt works

Tags (1)
0 Karma
1 Solution

jitendragupta
Path Finder

Try renaming:

| stats count as NbHostHealthInf85 
 | appendcols 
     [| inputlookup host.csv 
     | stats count as NbIndHost] 
 | eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85) 
 | eval NbHostHealthSup85=NbHostHealthSup85, NbHostHealthInf85=NbHostHealthInf85 
 | table NbHostHealthSup85 NbHostHealthInf85  
| rename NbHostHealthSup85 as ">85%", NbHostHealthInf85 as "<85%"
 | transpose

View solution in original post

0 Karma

jitendragupta
Path Finder

Try renaming:

| stats count as NbHostHealthInf85 
 | appendcols 
     [| inputlookup host.csv 
     | stats count as NbIndHost] 
 | eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85) 
 | eval NbHostHealthSup85=NbHostHealthSup85, NbHostHealthInf85=NbHostHealthInf85 
 | table NbHostHealthSup85 NbHostHealthInf85  
| rename NbHostHealthSup85 as ">85%", NbHostHealthInf85 as "<85%"
 | transpose
0 Karma

jip31
Motivator

perfect thanks

0 Karma

snigdhasaxena
Communicator

Hi,
Since | stats count as "<85%" this will create a field named ,"<85%" and field name should not start with a relational operator hence it doesn't work. Try naming the count field as something "Lessthan85" and it will work

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...