Dashboards & Visualizations

help for changing the label of a pie chart

jip31
Motivator

hello
I use the stats below in order to display a pie chart with 2 labels

| stats count as NbHostHealthInf85 
| appendcols 
    [| inputlookup host.csv 
    | stats count as NbIndHost] 
| eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85) 
| eval NbHostHealthSup85=NbHostHealthSup85, NbHostHealthInf85=NbHostHealthInf85 
| table NbHostHealthSup85 NbHostHealthInf85 
| transpose

I need to replace NbHostHealthSup85 by >85% and NbHostHealthInf85 by <85%
What is the good way to do this because I m doing for example | stats count as "<85%" but it doesnt works

Tags (1)
0 Karma
1 Solution

jitendragupta
Path Finder

Try renaming:

| stats count as NbHostHealthInf85 
 | appendcols 
     [| inputlookup host.csv 
     | stats count as NbIndHost] 
 | eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85) 
 | eval NbHostHealthSup85=NbHostHealthSup85, NbHostHealthInf85=NbHostHealthInf85 
 | table NbHostHealthSup85 NbHostHealthInf85  
| rename NbHostHealthSup85 as ">85%", NbHostHealthInf85 as "<85%"
 | transpose

View solution in original post

0 Karma

jitendragupta
Path Finder

Try renaming:

| stats count as NbHostHealthInf85 
 | appendcols 
     [| inputlookup host.csv 
     | stats count as NbIndHost] 
 | eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85) 
 | eval NbHostHealthSup85=NbHostHealthSup85, NbHostHealthInf85=NbHostHealthInf85 
 | table NbHostHealthSup85 NbHostHealthInf85  
| rename NbHostHealthSup85 as ">85%", NbHostHealthInf85 as "<85%"
 | transpose
0 Karma

jip31
Motivator

perfect thanks

0 Karma

snigdhasaxena
Communicator

Hi,
Since | stats count as "<85%" this will create a field named ,"<85%" and field name should not start with a relational operator hence it doesn't work. Try naming the count field as something "Lessthan85" and it will work

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...