Splunk Enterprise

How to color code column using expression(without JS) ?

sangs8788
Communicator

Hi

I have a table which displays duration for each category. I would like color code fields based on its duration.

Screenshot 2020-06-09 at 6.30.57 PM.png

In the above screenshot, how do I write an expression to color code which are exceeding 1min.

I would prefer using the color coding from the source rather than creating JSS because we dont have the permission to splunk servers as such to update config/put the JS scripts. Could someone please help me out here

Labels (1)
0 Karma

twesty
Path Finder

You can edit the table in the UI editor and select the column header for some coloration options.

Screenshot 2020-06-12 at 09.50.28.png

 

They are a little on the limited side but as far as I know, thats the best option there is. When you have selected a coloration, I would check the xml in the back to see whether there's further control within the table for extra params.

The docs here may also be of use: https://docs.splunk.com/Documentation/Splunk/latest/Viz/ChartConfigurationReference

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...