Splunk Search

pie chart color with eval condition

surekhasplunk
Communicator

Am using query "index=level3 host=Test | stats count by Age | sort Age" and visualizing it in a pie chart.

Now my requirement is I want to put some condition and color code it accordingly and show the result as in figure: Age
alt text

what query should I use and what xml editing should I do .

Currently using the query am getting result as shown in Fig: res
alt text

Tags (3)
0 Karma
1 Solution

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 

View solution in original post

JDukeSplunk
Builder

You will need to save it as a dashboard panel first of all. Once there, you can edit the charting options to define the colors.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/Chartcustomization#Chart_colors

You may also want to use rangemap to break down the days into the sizes you want.

http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Rangemap

Ive only ever done rangemap inline, so something similar to this. You're going probably going to have to tweak this to make it work.

index=level3 host=Test |rangemap AgeRange=count(Age) Under_3=0-3 4to7=4-7 Over=8-9999| chart count by AgeRange 
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...