Splunk Search

pie chart color with eval condition

surekhasplunk
Communicator

Am using query "index=level3 host=Test | stats count by Age | sort Age" and visualizing it in a pie chart.

Now my requirement is I want to put some condition and color code it accordingly and show the result as in figure: Age
alt text

what query should I use and what xml editing should I do .

Currently using the query am getting result as shown in Fig: res
alt text

Tags (3)
0 Karma
1 Solution

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 

View solution in original post

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...