Splunk Search

How do I change the names in the popup while keeping the legend names the same?

dhruv101
Path Finder

When we plot a chart like this

| chart count time phase

Lets say the legend appears as
Foo
Bar
Hey
Day

When I hover over the columns, I see popups like
time: ....
Foo: 1

time: ....
Bar: 3

I want to change the names in the popup while keeping the legend names the same(which means replace would not work). How do I go about this?

Legend names still stay Foo Bar Hey Day
But names in popup look like Foo-1 Bar-1 Hey-1 Day-1

Thanks.

felipesewaybric
Contributor
0 Karma

poete
Builder

Hello @dhruv101,

can you please reword your question in order to include the answers to @niketnilay comments, and make astatement of what you expect to see in the tooltips?

0 Karma

Noah_Woodcock
Path Finder

I definitely think more details are needed.

0 Karma

vidhyaArumalla
Path Finder

More details will help in providing more accurate solution

0 Karma

@dhruv101, please add more details.

Do you just want to take out time from theTooltip Text or do you want to have all Series to display count as 1?

I could see Bar: 3 in your question but in your request you asked for Bar: 1 is it typo or requirement?

You can refer to this answer by @Jeffland to change the chart Tooltip text: https://answers.splunk.com/answers/337329/is-it-possible-to-show-a-custom-tooltip-whenever-a.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

dhruv101
Path Finder

Hey @niketnilay
Its not Bar : 1. Its Bar-1 : 3, that is the name appearing on the popup needs to be Bar-1 while the one showing on legend should be Bar.
Thanks.

0 Karma

@dhruv101, so are you saying that the values for phase itself is Bar-1, Hey-1 and Day-1 etc? While you want them to appear as is in Tooltip, you want them to be different in Legends as Bar, Hay and Day?
Or is the requirement just the opposite?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...