> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Visualize proportional data with pie charts

> Create and customize pie chart data visualization panels for Palo Alto Networks Cortex XCOR dashboards.

<Note>
  [Classic dashboards](/observe/dashboards/classic-dashboards) have their own panels
  and methods of configuring them. For details about panels in classic dashboards,
  see [Classic dashboard panels](/observe/dashboards/classic-dashboards/classic-panels).
</Note>

Pie charts help you quickly view and compare a limited number of data segments by
category. A *pie chart panel* visualizes data returned by a [query](/investigate/querying)
as mutually exclusive, relatively proportional segments of a total amount. Each
segment's size corresponds to the proportion of the result's whole.

To visualize large numbers of categories or categories that aren't mutually
exclusive, or when you need to compare exact numbers with precision, consider using
categorical [bar charts](/observe/dashboards/panels/bar-chart) instead.

To create a pie chart or learn more about the configuration options common
to all panels, see [Panels](/observe/dashboards/panels).

## Use a pie chart's tooltip

When you hold the pointer over a segment in a pie chart, Palo Alto Networks Cortex XCOR
displays a tooltip that shows the segment's full label and value. If the segment
is aggregated, the tooltip lists the top 10 series within the aggregation.

## Pie chart queries

Pie charts use one or more
[queries](/observe/dashboards/panels#change-a-panels-query) to retrieve data to
visualize. Pie charts use the following query **Options** to refine the
displayed information, depending on your **Datasource**:

<Tabs>
  <Tab title="Metrics (Prometheus)" id="queries-metrics">
    * **Series naming**: Select a method to filter for metrics:
      * **Labels** require a **Naming pattern**. Use `{{ label_name }}` to include a
        label value. For example, `{{ env }}` will be replaced with values like staging-1, prod-1.
      * **Regex**: Use a [regular expression](/investigate/querying/regular-expressions)
        in the **Regex** text field to match a time series. You can also use a
        **Naming pattern** to rename series using capture groups.

    - **Query type**: In the collapsible **Options** at the bottom of the **Query**
      tab, select the [PromQL query](/investigate/querying/promql#basic-querying) type:

      * **Instant**: Query for the latest value in the time range.
      * **Range**: Query for values across the time range. When you select **Range**,
        also set **Reduce values in time range to** to choose how Cortex XCOR
        reduces each series to a single value:

        * **Avg**: The series' mean value, excluding null values.
        * **First**: The series' first value.
        * **First \***: The series' first numeric value.
        * **Last**: The series' last value.
        * **Last \***: The series' last numeric value.
        * **Min**: The series' minimum value.
        * **Max**: The series' maximum value.
        * **Total**: The total of all values in the series.

    - **Min step**: The minimum step for the PromQL query. This option appears when
      **Query type** is **Range**.

    * **Truncation strategy**: Truncation strategy to apply to the query. This modifies
      the raw query. Cortex XCOR selects the best strategy for fit when
      possible, and displays `Auto` as the selected strategy.

      Available strategies are:

      * `Auto`
      * `Off`
      * `Avg`
      * `Min`
      * `Max`

      Changing your truncation strategy adds truncation information as additional bands
      or bars on your chart and details into the legend.
  </Tab>

  <Tab title="Logs" id="queries-logs">
    * **Series naming**: Select a method to filter for metrics:
      * **Labels** require a **Naming pattern**. Use `{{ label_name }}` to include a
        label value. For example, `{{ env }}` will be replaced with values like staging-1, prod-1.
      * **Regex**: Use a [regular expression](/investigate/querying/regular-expressions)
        in the **Regex** text field to match a time series. You can also use a
        **Naming pattern** to rename series using capture groups.

    - **Reduce values in timeframe to**: When a logs query uses `make-series`, choose
      how Cortex XCOR reduces each series to a single value:

      * **Avg**: The series' mean value, excluding null values.
      * **First**: The series' first value.
      * **Last**: The series' last value.
      * **Min**: The series' minimum value.
      * **Max**: The series' maximum value.
      * **Total**: The total of all values in the series.
  </Tab>
</Tabs>

## Configure a pie chart

You can configure a pie chart by [modifying its <Icon icon="settings" /> **Settings**](/observe/dashboards/panels#edit-a-panel).

Cortex XCOR doesn't fully support directly editing a panel's JSON
representation. To configure a panel, edit it and modify individual fields. Use the JSON
representation only for managing your configuration as code with tools such as
[Chronoctl](/tooling/chronoctl) and [Terraform](/tooling/infrastructure/terraform).

To modify a pie chart's settings using its **Settings** tab:

1. [Edit the pie chart panel](/observe/dashboards/panels#edit-a-panel).
2. In the **Edit panel** interface, click the **Settings** tab.
3. Make your changes.
4. In the **Edit panel** interface, click **Apply** to save your changes.
5. After you've finished editing the panel, click **Save** on the dashboard to save
   your changes.

### Modify a pie chart's legend

The **Legend** section in a pie series chart's **Settings** tab controls whether
to display a legend alongside the chart, and if so it also configures where and
how the legend is displayed.

* **Show**: Toggles whether to display the legend. Defaults to enabled.
* **Position**: Selects whether to display the legend at the **Bottom** or to the
  **Right** of the chart. Defaults to **Bottom**.
* **Mode**: Selects whether to display the legend as a **List** of categories with
  a color swatch associating it with a line or bar on the chart, or as a **Table**
  with a header row. Defaults to **List**.
* **Size**: Defines the legend's size relative to the chart as either **Small**
  or **Medium**. Defaults to **Small**.

### Modify a pie chart's visual representation

The **Visual** section in a pie chart's **Settings** tab controls how
Cortex XCOR visualizes the query's pie results in the chart.

* **Display**: Determines how the chart visualizes the data. Defaults to **Auto**,
  which displays a sunburst chart when the query is grouped by two or more labels and a
  pie chart otherwise. For all the available options, see [Display data as a sunburst
  chart](#display-data-as-a-sunburst-chart).
* **Show series name**: Toggles whether the series name is displayed next to the
  segment.
* **Color Palette**: Determines the chart's color palette. The **Classic** palette
  uses six colors and prioritizes readability. The **Consistent** palette
  includes more colors and lets you assign a color to a series consistently across
  multiple panels. The **Status-neutral** palette excludes red, orange, and green
  to help distinguish between the chart's values and status indicators. Defaults to **Classic**.

#### Display data as a sunburst chart

The **Display** setting can visualize the query results as a *sunburst* chart for
hierarchical data. A sunburst chart represents each grouped label as a concentric
ring, with the innermost ring showing the first grouped label and each outer ring
adding the next label.

The **Display** setting offers the following options:

* **Auto**: (default) Displays a sunburst chart when the query is grouped by two or more labels
  and a pie chart otherwise.
* **Pie**: Displays a filled pie chart.
* **Donut**: Displays a pie chart with a hollow center.
* **Sunburst**: Displays a sunburst chart. This option requires a query grouped
  by two or more labels, for example, `sum by(region, service)`. If the query
  isn't grouped by at least two labels, the panel displays a pie chart instead and
  shows a warning.

A sunburst chart's rings follow the query's grouping order, with the first grouped
label in the innermost ring. A sunburst chart displays a maximum of four rings. If
a query is grouped by more than four labels, the panel ignores the additional labels.
When multiple queries feed the same panel, each query must be grouped by the same labels
in the same order. Series that are missing one of the grouped labels are collected
into a `(none)` segment so the rings total the same amount as the equivalent pie chart.

### Modify a pie chart's other features

The **Options** section in a pie chart's **Settings** tab controls other features
related to the chart's labels and units.

* **Label format**: Determines whether a segment's value label should be depicted
  as a **Percent**, the raw **Value**, or **Both** at once.

  Percent and Value labels each have their own options, listed under the **Percent**
  and **Value** subsections.

  * For both Value and Percent labels, **Decimals** determines the maximum number
    of decimal places to render. The resulting decimal places might be fewer than
    the selected value because Cortex XCOR doesn't render trailing zeros
    in decimal places.

    For example, when **Decimals** is set to **2**, the panel renders the value
    `1.5` as **1.5**, the value `1.55` as **1.55**, and `1.555` as **1.56**.

    You can choose from **0** to **4** maximum decimal places, or **Max**, which
    displays up to 20 decimal places.
  * For Value labels, you can configure additional settings:
    * **Unit**: Defines the value's unit. Defaults to `Decimal`.
    * **Decimal**: Displays values using base 10 units. For example, Cortex XCOR
      renders a decimal value of `1000000` as `1M` when **Abbreviate** is enabled.
    * **Bytes**: Displays values using decimal multiple-byte units.
    * **Time**: Determines the [unit of time](/overview/concepts/time-units)
      that Cortex XCOR uses to interpret a numeric value.
    * **Percent**: Interprets the value as a percentile, representing 0% to 100% on
      a range of either 0.0 to 1.0 (**Percent (0.0-1.0)**) or 0 and 100 (**Percent (0-100)**).

      For example, Cortex XCOR renders a value of `1.0` in
      **Percent (0.0-1.0)** as `100%`, and in **Percent (0-100)** as `1%`.
    * **Abbreviate**: Toggles whether to abbreviate units. For example,
      if you enable Abbreviate, Cortex XCOR renders a value of `100000000`
      as `100M`. You can toggle this setting only if you set the Unit to `Decimal`
      or `Bytes`; `Time` units are always abbreviated and `Percent` values don't require
      it. Defaults to `true`.
    * **Aggregate when % is \<=**: Defines the percentile threshold at which the chart
      aggregates the smallest categories into a single segment. Categories with a
      percentile value smaller than this setting are consolidated into a single
      segment on the chart. Defaults to `3`.

To discard your changes and restore the panel's settings to their defaults, click
**Reset to defaults**.


## Related topics

- [Visualize relative data with bar charts](/observe/dashboards/panels/bar-chart.md)
- [Visualize dashboard contents with panels](/observe/dashboards/panels.md)
- [Search and filter log data](/investigate/querying/query-logs.md)
- [Visualize time series with charts](/observe/dashboards/panels/time-series-chart.md)
- [Visualize values in ranges with gauge charts](/observe/dashboards/panels/gauge-chart.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.