Splunk Search

How to create a timechart with charting.legend.labels, but maintain the x-axis label format and color two lines red and blue?

hunyady
Explorer

I have a timechart with two lines (sum and max of values). Have a problem with the display format of the x-axis. It is now: ddd mm.yy (11. Okt 15).
If I insert a line of

<option name ="charting.legends.labels">[field_kum,field_sum]</option> 

then the display format of the x-axis changes: i.E. 2015-10-15T00:00:00.0000 +02. Why?
Can anybody help me?
I need it, while I must have the line color for the two fields exactly as red and blue. If I don't have this label-line, then it will be randomly blue/red or red/blue... 😞
I must use a timechart, not a chart!
thank you

0 Karma

mporath_splunk
Splunk Employee
Splunk Employee

You can always set explicit mapping for your charting series like so:

<option name="charting.fieldColors">
    {"field_kum":0xFF0000,"field_sum":0x0000FF}
</option>

That will always set field_kum to red and field_sum to blue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...