Splunk Search

pie chart color with eval condition

surekhasplunk
Communicator

Am using query "index=level3 host=Test | stats count by Age | sort Age" and visualizing it in a pie chart.

Now my requirement is I want to put some condition and color code it accordingly and show the result as in figure: Age
alt text

what query should I use and what xml editing should I do .

Currently using the query am getting result as shown in Fig: res
alt text

Tags (3)
0 Karma
1 Solution

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 

View solution in original post

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 
Get Updates on the Splunk Community!

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...