Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I get my Alert Level column chart results change color based on the value?

$
0
0
Hi All, I want to have search results (Alert Level column) with colors, so the Alert Level result should show Critical as RED, Warning as AMBER, and Normal as GREEN. How do I create a dashboard result value with colors? Below is my search. Please help. index=myindex sourcetype="mysource" msg=Failure* | eval Date=strftime(_time, "%Y/%m/%d") | stats count as fails by user, msg, Date, shost | eval "Alert Level"=case(fails>=10, "Critical", fails<5 AND fails>=10, "Warning", fails<5, "Normal") | table Date, msg, user, shost, fails, "Alert Level"| sort - fails | rename fails as "Failed Logon Attempts" | sort - count | rename user as "Account in Question", msg as "Message", shost as HostName Thanks in advance!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>