Is there any way to tell Splunk to automatically assign different colors to columns in a chart?
I created a chart, and they all use the same colors.
if you chart "by" a field, each "by" value gets a new series and thus a new color. if you're plotting the same value for a single series, it will just one color for the entire series. so it would be helpful to know what your query is.
if you chart "by" a field, each "by" value gets a new series and thus a new color. if you're plotting the same value for a single series, it will just one color for the entire series. so it would be helpful to know what your query is.
I over-complicated it. This does the same, and is easier to understand:
index=coreops sourcetype="snmp_stats" tag::host="ERA_Full" | head 7 | eval xlabel=""| chart sum(CONNECTIONS) by xlabel,HOST | rename xlabel AS HOST
"rename" is just used to name the x-axis. You can also use:
index=coreops sourcetype="snmp_stats" tag::host="ERA_Full" | head 7 | eval xlabel=HOST| chart sum(CONNECTIONS) by xlabel,HOST | rename xlabel AS HOST
which will puts non-empty HOST labels on each column, which may be nicer than the previous, which just sets them to empty. (Though the legend is still there.)
Wow. OK, that did it. Any chance you can explain that?
ah, try adding this:
index=coreops sourcetype="snmp_stats" tag::host="ERA_Full" | head 7 | chart sum(CONNECTIONS) as CONNECTIONS by HOST | eval H=HOST | eval HOST="" | xyseries HOST H CONNECTIONS
this did the trick!! wonderful
Nothing changed...
Try:
index=coreops sourcetype="snmp_stats" tag::host="ERA_Full" | head 7 | chart sum(CONNECTIONS) as CONNECTIONS by HOST
or max(CONNECTIONS) or avg(CONNECTIONS) as appropriate (though in your case it's going to be the same).
Here's the query:
index=coreops sourcetype="snmp_stats" tag::host="ERA_Full" |fields HOST, CONNECTIONS |table HOST, CONNECTIONS |head 7
I'm trying to duplicate a report that is done in Excel manually, and the customers want the values in different colors.