I created a dashboard for 24 hours and also 10 mins dashboard which I merged to the existing one. I need the dashboard colors to be based on threshhold (last seen 24 hours red, last seen 10 mins green). I know I can enter the color entries by editing XML. I entered it but I am having invalid error message. Please how can I do it in XML edit or maybe Format visualization? My splunk queries are: For 24 hour monitoring: | tstats latest(_time) as latest where index=* earliest=-48h by host | eval minutesago=round((now()-latest)/60,0) For 10 mins monitoring: | tstats latest(_time) as latest where index=* earliest=-10m by host | eval minutesago=round((now()-latest)/60,0)
... View more