Getting Data In

What different colors for bar graph

eholz1
Builder

Hello All.

I have a search: source="/var/log/squid/access.log" url NOT "esrs3-*" status = * | chart Count by status

This gives me a bar chart of the count of various http status codes, 200, 502, etc.

I want to divide the count by 100 if the count is greater than 300. and I would like to have a different color for each bar in the graph. there is only 1 field (count), is there a way I can get a different color for each status code which appears on the x-axis?  I have seen the series.Color command, but not sure how to apply it.

 

Thanks

EWH

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...