Splunk Search

How to apply color to a field with multiple values appended together?

kavyamohan
Explorer
JobExecutionTime
2652.180000
3462.840000
823.780000

I have a field named JobExecutionTime and i have it as a list of values not as seperate rows, How Can i apply color to the values based on some range. I have tried colorpalette rangemap but none seems to work but for seperate rows it is working(by which i mean is that if it is a single row with all values appended rangemap and color palette is not working. However if i have multiple rows with one value in each row rangemap and colorpalette is working). I do not need js and css as it won't be able for client to edit if they need to change the range.

0 Karma

aberkow
Builder

What would you want the range to be? I would imagine you either want to take the min, max, or average in a stats command, or you would want to separate each of these into their own rows with an mvexpand command. I don't know if applying a single value range over a multivalue field makes sense to Splunk

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...