Splunk Search

Dynamic assignment of Right Y-axis parameter

andykuhn
Path Finder

Like the example here (http://docs.splunk.com/Documentation/Splunk/6.2.3/Viz/Chartcontrols), I need to assign a parameter to the right-side y-axis. However, I would like the value to be dynamically selected by the user and not pre-configured as in the example. Assigning the dynamic token containing the value to the Overlay does not work (only parameters defined are selectable in the GUI) as the token does not appear to resolve to a value. Is it correct that the only way to accomplish this is to use the input selector (for the right y-axis) post-search? Redrawing the panel using javascript, passing in this token value as the 'overlay' field? I want the user to be able to select which parameter is graphed on the right y-axis on-the-fly.

0 Karma

andykuhn
Path Finder

I've answered my own question I think. The solution basically involves modification of the user interface such that the user is required to input ALL possible options first, then pass this subset (via cascading search, as per 6.x dashboard examples) to another input which is then coded as the 'overlay' value. Here is the functioning panel

<panel>
  <input type="time" token="time_token3">
    <label>Select a Time Range</label>
    <default>
      <earliestTime>-30d@d</earliestTime>
      <latestTime>now</latestTime>
    </default>
  </input>
  <input type="multiselect" token="lab_param_token2" searchWhenChanged="true">
    <label>Select Analyte(s)</label>
    <choice value="*">All</choice>
    <populatingSearch earliest="-6mon" latest="now" fieldForLabel="lab_param" fieldForValue="lab_param">`wtms_labdata` | fields lab_param | stats count by lab_param</populatingSearch>
    <default>Alkalinity</default>
    <valuePrefix>lab_param="</valuePrefix>
    <valueSuffix>"</valueSuffix>
    <delimiter> OR </delimiter>
  </input>
  <input type="multiselect" token="lab_param_token3" searchWhenChanged="true">
    <label>Select Analyte - Right Axis</label>
    <populatingSearch fieldForLabel="lab_param" fieldForValue="lab_param">`wtms_labdata` $lab_param_token2$ | fields lab_param | stats count by lab_param</populatingSearch>
  </input>
  <chart>
    <title>Multiple Analytes by $lab_location_token$</title>
    <searchString>`wtms_labdata` treatment_plant="$treatment_plant_token$" $lab_location_token$  $lab_param_token2$ | timechart span=1h values(result) by lab_param</searchString>
    <earliestTime>$time_token3.earliest$</earliestTime>
    <latestTime>$time_token3.latest$</latestTime>
    <option name="wrap">true</option>
    <option name="rowNumbers">false</option>
    <option name="dataOverlayMode">none</option>
    <option name="count">10</option>
    <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
    <option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
    <option name="charting.axisTitleX.visibility">visible</option>
    <option name="charting.axisTitleY.visibility">visible</option>
    <option name="charting.axisTitleY2.visibility">visible</option>
    <option name="charting.axisX.scale">linear</option>
    <option name="charting.axisY.scale">linear</option>
    <option name="charting.axisY2.enabled">true</option>
    <option name="charting.axisY2.scale">inherit</option>
    <option name="charting.chart">line</option>
    <option name="charting.chart.nullValueMode">connect</option>
    <option name="charting.chart.sliceCollapsingThreshold">0.01</option>
    <option name="charting.chart.stackMode">default</option>
    <option name="charting.chart.style">shiny</option>
    <option name="charting.drilldown">none</option>
    <option name="charting.layout.splitSeries">0</option>
    <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
    <option name="charting.legend.placement">right</option>
    <option name="charting.chart.overlayFields">$lab_param_token3$</option>
  </chart>
</panel>
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...