Splunk Search

How to set the color of bars in a bar chart?

Explorer

I need a help.

For the below mentioned bar chart, I want to change the colors of bar.

Like:

No_of_Mod_Ops = 1 and 2 means it should be green
No_of_Mod_Ops = 1 and 2 means it should be amber
No_of_Mod_Ops = 4 and No Mod Op means it should be red

Search query is:

...|chart count as No_of_Events by host| join type=left max=0 host[search query |chart count as No_of_MOD_Ops by host]|eval No_of_MOD_Ops=coalesce(No_of_MOD_Ops,0)|eval No_of_MOD_Ops=if(No_of_MOD_Ops==0,"No Mod Op",if(No_of_MOD_Ops>=5,"More than 4",No_of_MOD_Ops))| chart count by No_of_MOD_Ops
Tags (3)
0 Karma

Builder
0 Karma