Splunk Search

Add image to search

pinzer
Path Finder

Hi, i need to add an image like green, yellow, red to a rangemap search. Instead of the string of the rangemap.

eventtype="searchIPS1" | chart count | rangemap field=count GREEN-IMAGE=1-30 YELLOW-IMAGE=31-39 RED-IMAGE=40-5900 default=GRAY-IMAGE


Something like this it's possible?
thanks

Tags (2)
0 Karma

hazekamp
Builder

If you are using the SingleValue module via Advanced XML on a Splunk dashboard you can override the default look/feel of the range via $SPLUNK_HOME/etc/apps/$your_app$/appserver/static/application.css.

We do this in ESS like so (here we are overriding the default low/elevated/severe values):

.SingleValue .severe {
    background-color: transparent;
    background-image: url('images/high.png');
    color: #333333;
}

.SingleValue .elevated {
    background-color: transparent;
    background-image: url('images/medium.png');
    color: #333333;
}

.SingleValue .low {
    background-color: transparent;
    background-image: url('images/low.png');
    color: #333333;
}

There are some advanced things you can do as well...For instance, SingleValue takes an "additionalClass" parameter such that you can specify "An optional additional css class name to add to the result container".

See also: http://www.splunk.com/base/Documentation/4.2/Developer/AddASingleButton

0 Karma

ftk
Motivator

Take a look at the iconify search command. You may be able to achieve your goal with it.

0 Karma

pinzer
Path Finder

thanks but is not what i'm searching

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...