Splunk Search

Add image to search

pinzer
Path Finder

Hi, i need to add an image like green, yellow, red to a rangemap search. Instead of the string of the rangemap.

eventtype="searchIPS1" | chart count | rangemap field=count GREEN-IMAGE=1-30 YELLOW-IMAGE=31-39 RED-IMAGE=40-5900 default=GRAY-IMAGE


Something like this it's possible?
thanks

Tags (2)
0 Karma

hazekamp
Builder

If you are using the SingleValue module via Advanced XML on a Splunk dashboard you can override the default look/feel of the range via $SPLUNK_HOME/etc/apps/$your_app$/appserver/static/application.css.

We do this in ESS like so (here we are overriding the default low/elevated/severe values):

.SingleValue .severe {
    background-color: transparent;
    background-image: url('images/high.png');
    color: #333333;
}

.SingleValue .elevated {
    background-color: transparent;
    background-image: url('images/medium.png');
    color: #333333;
}

.SingleValue .low {
    background-color: transparent;
    background-image: url('images/low.png');
    color: #333333;
}

There are some advanced things you can do as well...For instance, SingleValue takes an "additionalClass" parameter such that you can specify "An optional additional css class name to add to the result container".

See also: http://www.splunk.com/base/Documentation/4.2/Developer/AddASingleButton

0 Karma

ftk
Motivator

Take a look at the iconify search command. You may be able to achieve your goal with it.

0 Karma

pinzer
Path Finder

thanks but is not what i'm searching

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...