Splunk Search

How to apply color to a field with multiple values appended together?

kavyamohan
Explorer
JobExecutionTime
2652.180000
3462.840000
823.780000

I have a field named JobExecutionTime and i have it as a list of values not as seperate rows, How Can i apply color to the values based on some range. I have tried colorpalette rangemap but none seems to work but for seperate rows it is working(by which i mean is that if it is a single row with all values appended rangemap and color palette is not working. However if i have multiple rows with one value in each row rangemap and colorpalette is working). I do not need js and css as it won't be able for client to edit if they need to change the range.

0 Karma

aberkow
Builder

What would you want the range to be? I would imagine you either want to take the min, max, or average in a stats command, or you would want to separate each of these into their own rows with an mvexpand command. I don't know if applying a single value range over a multivalue field makes sense to Splunk

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...