I use multiple saves searches from different chart to display overall application health status. The chart works fine for me accept it only shows colors. I am working to display the string value (green, yellow, red) on the pie chart but it doesnt work as expected.
Splunk pie chart (somehow) never displays the color name on the chart. I was wondering if there is a way to display the value on the chart. I tried to use the single value chart but looks like it adds colors only for numerical values and not for string.
Please help me understand if anyone of you have achieved this in Splunk. Here are some additional details.
| savedsearch "A"
| append [ | savedsearch "B"]
| append [ | savedsearch "C"]
| append [ | savedsearch "D"]
| append [ | savedsearch "E"]
| append [ | savedsearch "F"]
| append [ | savedsearch "G"]
| eval overall_health = min(availability_severity, performance_severity, apdex_severity, report_GCPA_severity, report_NBP_severity, report_OReq_severity, report_PGA_severity)
| stats min(overall_health) as severity
| eval color=case(severity="1","red",severity="2","yellow",severity="3","green")
| chart count by color
... View more