Splunk Search

How to use fieldcolors

ericvdhout
Path Finder

Hi,

 

In one of my graphs I try to fixate the areacolors to red and green. However, I can't figure out how.

Tried this:

 

 

 

"visualizations": {
		"viz_CgGpI6E0": {
			"type": "splunk.area",
			"dataSources": {
				"primary": "ds_aNB3d69r_ds_d4nLznpt"
			},
			"title": "Nanoservice request results",
			"options": {
				"stackMode": "stacked100"
			},
			"fieldColors": {
				"OKPerc": "#42663a",
				"ErrorPerc": "#7a1709"
			},
			"showProgressBar": false,
			"showLastUpdated": false
		},
		"viz_r9Pd57Q4": {
			"type": "splunk.markdown",
			"options": {
				"markdown": ""
			}
		}
	},

 

Also tried placing them inside the "Options" object.

	"visualizations": {
		"viz_CgGpI6E0": {
			"type": "splunk.area",
			"dataSources": {
				"primary": "ds_aNB3d69r_ds_d4nLznpt"
			},
			"title": "Nanoservice request results",
			"options": {
				"stackMode": "stacked100",
				"fieldColors": {
					"OKPerc": "#42663a",
					"ErrorPerc": "#7a1709"
				}
			},
			"showProgressBar": false,
			"showLastUpdated": false
		},
	},

 

But the colors stay wrong. Am I doing it wrong?

Current graph: 

ericvdhout_0-1652104750371.png

Purple should be green and blue should be red.

Cheers,

Labels (1)
0 Karma
1 Solution

ericvdhout
Path Finder

No idea what FieldColors does, but SeriesColors seems to be my friend.

 

 

 

		"viz_CgGpI6E0": {
			"type": "splunk.area",
			"dataSources": {
				"primary": "ds_aNB3d69r_ds_d4nLznpt"
			},
			"title": "Nanoservice request results",
			"options": {
				"stackMode": "stacked100",
				"seriesColors": "[#42663a,#7a1709]"
			},
			"showProgressBar": false,
			"showLastUpdated": false
		}

ericvdhout_0-1652106116022.png

 

View solution in original post

0 Karma

ericvdhout
Path Finder

No idea what FieldColors does, but SeriesColors seems to be my friend.

 

 

 

		"viz_CgGpI6E0": {
			"type": "splunk.area",
			"dataSources": {
				"primary": "ds_aNB3d69r_ds_d4nLznpt"
			},
			"title": "Nanoservice request results",
			"options": {
				"stackMode": "stacked100",
				"seriesColors": "[#42663a,#7a1709]"
			},
			"showProgressBar": false,
			"showLastUpdated": false
		}

ericvdhout_0-1652106116022.png

 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...