Splunk Search

How do I change the names in the popup while keeping the legend names the same?

dhruv101
Path Finder

When we plot a chart like this

| chart count time phase

Lets say the legend appears as
Foo
Bar
Hey
Day

When I hover over the columns, I see popups like
time: ....
Foo: 1

time: ....
Bar: 3

I want to change the names in the popup while keeping the legend names the same(which means replace would not work). How do I go about this?

Legend names still stay Foo Bar Hey Day
But names in popup look like Foo-1 Bar-1 Hey-1 Day-1

Thanks.

felipesewaybric
Contributor
0 Karma

poete
Builder

Hello @dhruv101,

can you please reword your question in order to include the answers to @niketnilay comments, and make astatement of what you expect to see in the tooltips?

0 Karma

Noah_Woodcock
Path Finder

I definitely think more details are needed.

0 Karma

vidhyaArumalla
Path Finder

More details will help in providing more accurate solution

0 Karma

niketn
Legend

@dhruv101, please add more details.

Do you just want to take out time from theTooltip Text or do you want to have all Series to display count as 1?

I could see Bar: 3 in your question but in your request you asked for Bar: 1 is it typo or requirement?

You can refer to this answer by @Jeffland to change the chart Tooltip text: https://answers.splunk.com/answers/337329/is-it-possible-to-show-a-custom-tooltip-whenever-a.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

dhruv101
Path Finder

Hey @niketnilay
Its not Bar : 1. Its Bar-1 : 3, that is the name appearing on the popup needs to be Bar-1 while the one showing on legend should be Bar.
Thanks.

0 Karma

niketn
Legend

@dhruv101, so are you saying that the values for phase itself is Bar-1, Hey-1 and Day-1 etc? While you want them to appear as is in Tooltip, you want them to be different in Legends as Bar, Hay and Day?
Or is the requirement just the opposite?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...