Splunk Search

How do I change the names in the popup while keeping the legend names the same?

dhruv101
Path Finder

When we plot a chart like this

| chart count time phase

Lets say the legend appears as
Foo
Bar
Hey
Day

When I hover over the columns, I see popups like
time: ....
Foo: 1

time: ....
Bar: 3

I want to change the names in the popup while keeping the legend names the same(which means replace would not work). How do I go about this?

Legend names still stay Foo Bar Hey Day
But names in popup look like Foo-1 Bar-1 Hey-1 Day-1

Thanks.

felipesewaybric
Contributor
0 Karma

poete
Builder

Hello @dhruv101,

can you please reword your question in order to include the answers to @niketnilay comments, and make astatement of what you expect to see in the tooltips?

0 Karma

Noah_Woodcock
Path Finder

I definitely think more details are needed.

0 Karma

vidhyaArumalla
Path Finder

More details will help in providing more accurate solution

0 Karma

niketn
Legend

@dhruv101, please add more details.

Do you just want to take out time from theTooltip Text or do you want to have all Series to display count as 1?

I could see Bar: 3 in your question but in your request you asked for Bar: 1 is it typo or requirement?

You can refer to this answer by @Jeffland to change the chart Tooltip text: https://answers.splunk.com/answers/337329/is-it-possible-to-show-a-custom-tooltip-whenever-a.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

dhruv101
Path Finder

Hey @niketnilay
Its not Bar : 1. Its Bar-1 : 3, that is the name appearing on the popup needs to be Bar-1 while the one showing on legend should be Bar.
Thanks.

0 Karma

niketn
Legend

@dhruv101, so are you saying that the values for phase itself is Bar-1, Hey-1 and Day-1 etc? While you want them to appear as is in Tooltip, you want them to be different in Legends as Bar, Hay and Day?
Or is the requirement just the opposite?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...