Splunk ITSI

IT Service Intelligence: How to change the color based on the value of a field (state)?

DataOrg
Builder

Below is the data I have in search time. I have the entity as a state column.
How can I make running as Green and Stopped as Red ?

ServiceType="Own Process"
StartMode="Manual"
Started=true
State="Running"
Status="OK"
ProcessId=20088
0 Karma
1 Solution

adonio
Ultra Champion

if you are asking regarding a KPI, i would probably convert the value of State field to a number
for example:
... your search ... | eval status=if(State''"Running",0,1) ...
then on the KPI i will have the max function and the field to report as status
when defining thresholds, normal will be 0 and High or Critical will be 1

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

if you are asking regarding a KPI, i would probably convert the value of State field to a number
for example:
... your search ... | eval status=if(State''"Running",0,1) ...
then on the KPI i will have the max function and the field to report as status
when defining thresholds, normal will be 0 and High or Critical will be 1

hope it helps

0 Karma

DataOrg
Builder

but in the KPI tile. the status will be shown as numeric value as 1 or 0. it there any way i can display the state and to calculate i can use status value?

0 Karma

adonio
Ultra Champion

ITSI KPIs working only on numeric values, you cant put a string (per-se) in the visualization as far as i know
meaning, you cant have a text in the KPI viz box

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...