Splunk Search

Need help on Dashboard related issue

Renunaren
Loves-to-Learn Everything

I have a dashboard in which there is a Pie chart like below 

Renunaren_0-1675663938155.png

I need help in this way that it has to show a label of event count and also the color details like green for success, blue for running, red for error, Orange for Wait. It has to mention the details and also the event count.

Also need help on the below issue for the bar chart.

Renunaren_1-1675664088266.png

 

In the above chart there are multiple columns with different colors for a single day. For this there should be a single column with different colors for single. Can someone please help me out on this.

 

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do you mean stacked mode?

ITWhisperer_0-1675671642023.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Renunaren,

the only way to have a legend with the values is to create another panel containing the same search (and results) in table format.

About colours, if the values are fixed (e.g. success, running, error, Wait, etc...) you can assign a values from the GUI, on the table clicking on the pen in the right high corner of the column:

gcusello_0-1675666149348.png

On the chart using the charting.fieldColors option:

    <option name="charting.fieldColors">
      {"ERROR": 0xFF0000, "WARN": 0xFF9900, "INFO":0x0066FF, "NULL":0xC4C4C0}
    </option>

Ciao.

Giuseppe

0 Karma

Renunaren
Loves-to-Learn Everything

Hi If possible can you please provide me a better solution for the issue merging of two columns in a column chart into a single chart

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...