Splunk Search

How to color code one column based on another (Dynamic)column when using chart command?

achoudhary1
New Member

I have 700 sites, I am running a chart command to get some value for each site per day.

| bin span=1d _time 
| eval _time=strftime(_time,"%Y-%m-%d") 
| chart avg(<somefieldname>) as Value by Site,_time 

Output looks like this:
alt text

Now I want to color my field values based on the delta between Field1 and rest values in the row. eg. If delta between -35 and -44 is 9 then -44 will be colored yellow. So the ranges are , Delta <=5 - No color ; 5>Delta<=10 - Yellow ; Delta>10 - Red.

alt text

How can I do this?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...