Dashboards & Visualizations

single rangemap displaying 'low' instead of number

lisheridan
Explorer

I have 3 single rangemap fields configured in a dashboard. All 3 field values are actually 0. However, one of the values (for delete) is always shown as 'low' instead of '0'.

Here is the search to verify values:
sourcetype=rfsctl-a* earliest=-24h | rex field=_raw "megastore.stats.decode_errors: (?\d+)" | rex field=_raw "megastore.stats.delete_errors: (?\d+)" | stats avg(decode_errors) as avg_decode_errors avg(delete_errors) as avg_delete_errors | eval display_value_delete = tostring(round(avg_delete_errors,0), "commas") | eval display_value_decode = tostring(round(avg_decode_errors,0), "commas")

--> with results
avg_decode_errors avg_delete_errors display_value_decode display_value_delete
0.000000 0.000000 0 0

display_value_delete shows as 'low' in the UI

Here is the xml:



sourcetype=rfsctl-a* earliest=-24h | rex field=_raw "megastore.stats.encode_errors: (?<encode_errors>\d+)" | stats avg(encode_errors) as avg_encode_errors | eval display_value_encode = tostring(round(avg_encode_errors,0), "commas")| rangemap field=display_value_encode low=0-1 elevated=2-10 severe=11-1000 default=low
Encode Errors
range


sourcetype=rfsctl-a* earliest=-24h | rex field=_raw "megastore.stats.decode_errors: (?<decode_errors>\d+)" | stats avg(decode_errors) as avg_decode_errors | eval display_value_decode = tostring(round(avg_decode_errors,0), "commas") | rangemap field=display_value_decode severe=11-1000 elevated=2-10 low=0-1 default=low
Decode Errors
range


sourcetype=rfsctl-a* earliest=-24h | rex field=_raw "megastore.stats.delete_errors: (?<delete_errors>\d+)" | stats avg(delete_errors) as avg_delete_errors | eval display_value_delete = tostring(round(avg_delete_errors,0), "commas") | rangemap field=display_value_delete severe=11-1000 elevated=2-10 low=0-1 default=low
Delete Errors
range

Tags (1)

mmelnick
Path Finder

Check out the answer from zeigfried:

http://splunk-base.splunk.com/answers/4450/single-values-rangemap-and-displaying-original-field-valu...

I think that's what you're after.

Takajian
Builder

Do you know "defalut=low" means? You may need to delete it in order to achieve your purpose?

... | rangemap field=display_value_encode low=0-1 elevated=2-10 severe=11-1000 default=low

Can you change the rangemap search as following and let me know if this sovle?

... | rangemap field=display_value_encode low=0-1 elevated=2-10 severe=11-1000

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...