Dashboards & Visualizations

colorpallette expression not matching field value

thaghost99
Path Finder

hi, need some help, i have this format type but it seems the word 'up' is not matching for whatever reason.

there is no spaces or anything in the field value. 

the field value is extracted using 'rex'.

i have this working in other fields, but this one got me stuck. 

any help will be appreciated. 

 

<format type="color" field="state">
<colorPalette type="expression">if (value == "up","#Green", "#Yellow")</colorPalette>
</format>

 

thaghost99_0-1709222707938.png

 

Labels (3)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

I don't believe you can use colour names, such as Green and Yellow, you have to use hex codes or RGB, see here

https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/TableFormatsXML#Color_palette_types_and...

in your case it's interesting that you have yellow, as I would expect black if it does not understand colour names.

Have you tried

<colorPalette type="expression">if(value == "up","#00FF00", "#FFFF00")</colorPalette>

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

I don't believe you can use colour names, such as Green and Yellow, you have to use hex codes or RGB, see here

https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/TableFormatsXML#Color_palette_types_and...

in your case it's interesting that you have yellow, as I would expect black if it does not understand colour names.

Have you tried

<colorPalette type="expression">if(value == "up","#00FF00", "#FFFF00")</colorPalette>

Richfez
SplunkTrust
SplunkTrust

What's the actual regex you are using to capture it?
And if you are sure you are using the right syntax because you copy pasted it from some working one - you could try to add | eval state = "up" as the last command in the search to force it to be "up" and see if that works.  If it doesn't, then I'd say there's something else wrong with that syntax.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...