如何在Sumo Logic仪表盘的SingleValue图表中添加工具提示详情?
Sumo Logic SingleValue图表工具提示配置问题解决
问题背景
在Sumo Logic仪表盘中创建的SingleValue图表可正常展示聚合百分比数据,但需要添加包含support_page_action_count、granular_action_count、tool_name等元数据的工具提示,当前查询添加hover_text字段后报错。
原查询语句
deployment=xyz container=abc zone=123 <SearchString> | json "log" as _raw nodrop | json auto | where tool_name = "ABC" | fields percentage_granularized, tool_name, granular_action_count, support_page_action_count | format( "Support Actions: {0}, Granular Actions: {1}, Tool Name: {2}", support_page_action_count, granular_action_count, tool_name ) as hover_text | pct(percentage_granularized) // 单独执行此步可正常显示SingleValue图表 // | fields avg(percentage_granularized), hover_text // 取消注释后抛出错误
报错信息
Field hover_text not found, please check the spelling and try again.
核心问题
- 如何在SingleValue图表中启用工具提示,展示
support_page_action_count、granular_action_count、tool_name等元数据? - SingleValue图表能否同时显示聚合值和
hover_text字段内容? - 有没有可行方案实现需求?
解决方案
报错原因
聚合函数(如pct())执行后,未被纳入聚合逻辑的非聚合字段(如hover_text)会被自动丢弃——因为聚合操作会将多行数据合并为一行,仅保留聚合计算结果,直接引用未保留的字段就会触发"字段未找到"错误。
可行实现方案
要同时保留聚合值和工具提示文本,需将元数据字段纳入聚合逻辑,以下是两种有效方法:
方法1:利用pct()的by子句保留元数据
如果tool_name、support_page_action_count、granular_action_count是固定值或可作为分组依据,可通过by子句将这些字段纳入聚合,之后再生成hover_text:
deployment=xyz container=abc zone=123 <SearchString> | json "log" as _raw nodrop | json auto | where tool_name = "ABC" | pct(percentage_granularized) by tool_name, granular_action_count, support_page_action_count | format( "Support Actions: {0}, Granular Actions: {1}, Tool Name: {2}", support_page_action_count, granular_action_count, tool_name ) as hover_text | fields _count, hover_text // _count是pct()生成的百分比字段,可按需调整字段名
- 逻辑:
by子句会让聚合操作保留指定的非聚合字段,后续生成的hover_text可被SingleValue图表识别为工具提示内容。
方法2:用stats函数同时完成聚合与元数据保留
如果元数据在所有数据行中是固定值,可使用stats函数一次性计算聚合值并保留元数据(用first()/last()提取固定值):
deployment=xyz container=abc zone=123 <SearchString> | json "log" as _raw nodrop | json auto | where tool_name = "ABC" | stats pct(percentage_granularized) as percentage_value first(support_page_action_count) as support_page_action_count first(granular_action_count) as granular_action_count first(tool_name) as tool_name | format( "Support Actions: {0}, Granular Actions: {1}, Tool Name: {2}", support_page_action_count, granular_action_count, tool_name ) as hover_text | fields percentage_value, hover_text
- 逻辑:
stats函数可同时处理聚合计算和元数据保留,生成的hover_text能直接被SingleValue图表用作工具提示。
核心问题解答
- 启用工具提示的方法:通过上述两种方法,先确保元数据字段在聚合后被保留,再用
format()生成hover_text字段,SingleValue图表会自动将该字段内容作为工具提示展示。 - 能否同时包含:可以,但必须通过聚合函数的
by子句或stats函数将元数据字段纳入聚合逻辑,不能直接在聚合后引用未被保留的非聚合字段。 - 可行解决办法:上述两种方案均可,若元数据是分组依据选方法1,若元数据为单值选方法2。
内容的提问来源于stack exchange,提问作者Shailesh Seth
相关产品推荐
相关产品推荐

