Dashboards & Visualizations

map visualization - regex for mapping.fieldColors

mikaelbje
Motivator

I'm trying to create a map visualization for different sites and I want to show each site name as well as their status on the map where status can be Up or Down. I'd like to color status Up green and status Down red. When I hover over a cluster/site I'd like to see the location name. I'm only able to get a count of Up/Down sites but without site names OR an overview of all sites but with no Up/Down info (I can always get the info in using an eval to include status into my location_name field, but this way I can't color it green/red.

Would it be possible to include support for regular expressions in mapping.fieldColors? I.e. instead of "Up:0xRRGGBB,Down:0xRR00FF", I could have "^.+ : Up$" and "^.+ : Down$" if I'd like to have let's say multiple fields returned to indicate location names + status (Up or Down) and I would like to color Up green and Down red but still show the location name.

SanthoshSreshta
Contributor

hi,.
i am also looking to add colors in geostats map.

here is the link for the question I had posted
http://answers.splunk.com/answers/236609/can-we-give-colors-in-geostats-based-on-ranges-of.html
if found please post the answer there .

0 Karma

xisura
Communicator

hi same situation here. Did you find a workaround or a solution in this ?

0 Karma

mikaelbje
Motivator

Finally found this! A little trick using xyseries might help you solve what you're trying to accomplish. It certainly helped me. Doesn't relly solve the regex part where field names might be dynamic though.

http://answers.splunk.com/answers/78397/changing-colors-in-a-column-chart.html

0 Karma

mikaelbje
Motivator

No, unfortunately a satisfactory solution was not found.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...