Hi !!
I am new to Splunk and trying to create a single value visualization with 2 values. ( ... | table first, second
)
The "first" value determines the value to be displayed.
The "second" value determines the color.
Currently, I am able to display the "first" value but the color is affected by the "first" value.
Is there any suggestion?
Thanks in advance 🙂
Single value panel accepts/recognizes only one value. Color is based on this single value. Your options are either to color the value or color the trend based on the value for the same field but in the next event. You can set ranges (format) to determine the color, but the range is based on the value in the first (only) field.
Single value panel accepts/recognizes only one value. Color is based on this single value. Your options are either to color the value or color the trend based on the value for the same field but in the next event. You can set ranges (format) to determine the color, but the range is based on the value in the first (only) field.
Thanks sundareshr.
Hi @weiquanswq - Did this answer provide the solution to your question? If yes, please don't forget to click "Accept" below this answer to resolve this post. Thanks!
how are the first and second values related? I could be mistaken, but I thought the single value only worked with one value - so the coloring would have to be based on that value.
Coloring by value requires stats
or timechart
. See Customize a single value in the Dashboards and Visualizations manual for complete information.
ChrisG,
I have modified the search to as such
| table id, first, second | stats values(first) as firstVal values(second) as secondVal by id
But it is still affected by firstVal