Splunk Search

SparkLine Formatting not working

hbpatel142
Engager

Form or Dashboard is not displaying the bar from the below query and configuration. Let me know what I am doing.

<row>
<table>
<searchTemplate>index="XXXXXXXXXX" $ApplicationGroup$ counter="% Processor Time" OR counter="% Committed Bytes In Use" OR counter="Total Method Requests/sec" | stats sparkline(avg(Value)) as Trending, perc90(Value) as value by host , counter </searchTemplate>
<title>Performance Counters by Host</title>
<format field="sparkline" type="sparkline">
<option name="type">bar</option>
<option name="height">30</option>
<option name="barColor">green</option>
</format>
</table>
</row>

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

As per http://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#Sparkline_opti... you're referring to the wrong field name in <format field="..."> and there's no option named barColor.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

As per http://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#Sparkline_opti... you're referring to the wrong field name in <format field="..."> and there's no option named barColor.

hbpatel142
Engager

Thanks for posting the reference link. I was not passing the field="" value properly and hence it was not working.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...