Splunk Search

Color results of pie chart based on a token

andres
Loves-to-Learn Lots

Hi,

My search returns a pie chart that is a sum of a variable (memory_usage_GB) and ploted by another variable (user).

....

| stats sum(memory_usage_GB) by user

....

On the other side, I have an input in the same dashboard where you can select a specific user. The input is referenced with the token $userfilter$.

I want the pie chart to color the result corresponding to the selected user in the input with one color, and all the other results with another color.

So in the XML of the pie chart, I have tried the following:

<option name="charting.fieldColors">{"$userfilter$": 0x39ff14,"all":0xa9a9a9}</option>

It colors the desired user. However,  I don't know how can I refer to the rest of the results.

Maybe there is another way to do the coloring in the search string?

Thank you!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...