Splunk Search

pie chart color with eval condition

surekhasplunk
Communicator

Am using query "index=level3 host=Test | stats count by Age | sort Age" and visualizing it in a pie chart.

Now my requirement is I want to put some condition and color code it accordingly and show the result as in figure: Age
alt text

what query should I use and what xml editing should I do .

Currently using the query am getting result as shown in Fig: res
alt text

Tags (3)
0 Karma
1 Solution

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 

View solution in original post

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...