> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Visualize large statistic numbers with stat charts

> Create and customize stat chart data visualization panels for Palo Alto Networks Cortex XCOR dashboards.

<Note>
  [Classic dashboards](/observe/dashboards/classic-dashboards) have their own panels
  and methods of configuring them. For details about panels in classic dashboards,
  see [Classic dashboard panels](/observe/dashboards/classic-dashboards/classic-panels).
</Note>

A *stat chart* in Palo Alto Networks Cortex XCOR visualizes statistic numbers returned
by a [query](/investigate/querying). The chart depicts a value based on the results of
the defined query. You can optionally add a sparkline chart that displays under the
value, in addition to displaying a message when the value hits a defined threshold.

To create a Stat chart or learn more about the configuration options common
to all panels, see [Panels](/observe/dashboards/panels).

## Stat chart queries

Stat charts use one or more
[queries](/observe/dashboards/panels#change-a-panels-query) to retrieve data to
visualize. Stat charts use the following query **Options** to refine the
displayed information, depending on your **Datasource**:

<Tabs>
  <Tab title="Metrics (Prometheus)" id="queries-metrics">
    * **Series naming**: Select a method to filter for metrics:
      * **Labels** require a **Naming pattern**. Use `{{ label_name }}` to include a
        label value. For example, `{{ env }}` will be replaced with values like staging-1, prod-1.
      * **Regex**: Use a [regular expression](/investigate/querying/regular-expressions)
        in the **Regex** text field to match a time series. You can also use a
        **Naming pattern** to rename series using capture groups.

    - **Query type**: In the collapsible **Options** at the bottom of the **Query**
      tab, select the [PromQL query](/investigate/querying/promql#basic-querying) type:

      * **Instant**: Query for the latest value in the time range.
      * **Range**: Query for values across the time range. When you select **Range**,
        also set **Reduce values in time range to** to choose how Cortex XCOR
        reduces each series to a single value:

        * **Avg**: The series' mean value, excluding null values.
        * **First**: The series' first value.
        * **First \***: The series' first numeric value.
        * **Last**: The series' last value.
        * **Last \***: The series' last numeric value.
        * **Min**: The series' minimum value.
        * **Max**: The series' maximum value.
        * **Total**: The total of all values in the series.

    - **Min step**: The minimum step for the PromQL query. This option appears when
      **Query type** is **Range**.

    * **Truncation strategy**: Truncation strategy to apply to the query. This modifies
      the raw query. Cortex XCOR selects the best strategy for fit when
      possible, and displays `Auto` as the selected strategy.

      Available strategies are:

      * `Auto`
      * `Off`
      * `Avg`
      * `Min`
      * `Max`

      Changing your truncation strategy adds truncation information as additional bands
      or bars on your chart and details into the legend.

    When a stat chart's [sparkline](#modify-a-stat-charts-properties) is enabled, the
    **Min step** option is always available, not only when **Query type** is **Range**.
  </Tab>

  <Tab title="Logs" id="queries-logs">
    * **Series naming**: Select a method to filter for metrics:
      * **Labels** require a **Naming pattern**. Use `{{ label_name }}` to include a
        label value. For example, `{{ env }}` will be replaced with values like staging-1, prod-1.
      * **Regex**: Use a [regular expression](/investigate/querying/regular-expressions)
        in the **Regex** text field to match a time series. You can also use a
        **Naming pattern** to rename series using capture groups.

    - **Reduce values in timeframe to**: When a logs query uses `make-series`, choose
      how Cortex XCOR reduces each series to a single value:

      * **Avg**: The series' mean value, excluding null values.
      * **First**: The series' first value.
      * **Last**: The series' last value.
      * **Min**: The series' minimum value.
      * **Max**: The series' maximum value.
      * **Total**: The total of all values in the series.
  </Tab>
</Tabs>

## Configure a stat chart

You can configure a stat chart by
[modifying its <Icon icon="settings" /> **Settings**](/observe/dashboards/panels#edit-a-panel).

See [Modify a stat chart's properties](#modify-a-stat-charts-properties) for a list
of the settings you can modify.

Cortex XCOR doesn't fully support directly editing a panel's JSON
representation. To configure a panel, edit it and modify individual fields. Use the JSON
representation only for managing your configuration as code with tools such as
[Chronoctl](/tooling/chronoctl) and [Terraform](/tooling/infrastructure/terraform).

### Modify a stat chart's properties

The **Visual** section in a stat chart's **Settings** tab defines how the stat interprets
and displays the panel's query results.

* **Layout**: Controls how the panel arranges its series. Choose **Cards** to display an
  individual stat for each series, with optional sparklines, or **Hexagons** to pack the
  series into a threshold-colored honeycomb grid. See [Display a stat chart as a honeycomb
  grid](#display-a-stat-chart-as-a-honeycomb-grid).
* **Sparkline**: Enables a sparkline visualization that displays under the value
  generated by the defined query.
* **Value font size**: Sets the font size of the displayed value. Defaults to
  **Default**, which sizes the value automatically.
* **Series name font size**: Sets the font size of the series name. Defaults to
  **Default**, which sizes the name automatically.
* **Message font size**: Sets the font size of a threshold message. Defaults to
  **Default**, which sizes the message automatically.
* **Series name**: Controls when the series name displays. Choose **Auto Show** to
  display the series name when there's enough space, **Always Show** to always display
  it, or **Never Show** to hide it.

- **Sort**: Determines the order in which the panel arranges its series:
  * **Default**: Original data order.
  * **Ascending (value)**: Lowest to highest value.
  * **Descending (value)**: Highest to lowest value.
  * **Ascending (A→Z)**: Series name from A to Z.
  * **Descending (Z→A)**: Series name from Z to A.

When **Layout** is set to **Hexagons**, the **Sparkline** and font size options
don't apply and are hidden, because hex cells auto-size their text and never draw
sparklines.

### Display a stat chart as a honeycomb grid

Set **Layout** to **Hexagons** to render the panel's series as a dense honeycomb
grid instead of individual stat cards. Each series becomes a single hexagonal cell,
filled with the [threshold](#modify-a-stat-charts-thresholds) color that matches its
current value, so you can scan the state of a large number of series at once.

In the **Hexagons** layout:

* Each cell displays its value and, depending on the available space and the
  **Series name** setting, its series name. Hover over a cell to see its details in
  a tooltip.
* Cell text scales automatically to fit, so the **Sparkline** and font size settings
  don't apply and are hidden. Any sparkline you previously configured is removed when
  you switch to this layout.
* Cells are colored by threshold. The panel background isn't tinted and threshold messages
  aren't displayed. Define the colors used for the cells in the
  [**Thresholds**](#modify-a-stat-charts-thresholds) section.

In the panel's JSON representation, the **Hexagons** layout is stored as
`layout: Hexagon`. The default **Cards** layout omits the `layout` field.

#### Group honeycomb cells into sections

When a stat chart uses the **Hexagons** layout, Cortex XCOR
automatically arranges the honeycomb into labeled sections. This layout
produces a view that keeps related series together without having to
configure a setting. The grouping isn't stored in the panel's JSON
representation.

Cortex XCOR groups cells automatically from the panel's query results:

* If the panel's queries share a grouping dimension, such as
  `chronosphere_k8s_cluster`, cells are grouped by that dimension. When every
  query agrees on an ordered set of dimensions, Cortex XCOR groups by
  more dimensions only when the additional levels reveal more structure.
* If the queries don't provide grouping dimensions, the panel groups by a single
  shared label when one label is an unambiguous choice.

Each section is a labeled card, and sections are arranged in a responsive,
multicolumn layout. A section heading shows each grouping label and its value in
the form `label: value`, such as `chronosphere_k8s_cluster: prod`. When grouping
uses multiple dimensions, the heading joins each `label: value` pair with a slash,
such as `chronosphere_k8s_cluster: prod / namespace: web`. When a series has no
value for a grouping label, that label's value displays as `(none)`, such as
`chronosphere_k8s_cluster: (none)`. The
[**Sort**](#modify-a-stat-charts-properties) option applies within each section.

When grouping isn't possible or wouldn't be readable, the panel displays a single
flat honeycomb grid instead due to one of the following conditions:

* The queries disagree on their dimensions or provide no clear grouping.
* Grouping would produce fewer than two sections.
* Grouping would produce more than 12 sections.
* Grouping would produce many very small sections. Grouping requires roughly two
  or more cells per section on average.

### Modify a stat chart's units and formatting

The **Unit and formatting** section changes the display of units on the chart.

* **Unit**: Defines the unit used to render the Y-axis. This has the most significant
  effect when you enable Abbreviate. Defaults to `Decimal`.
  * **Decimal**: Base 10 values. Cortex XCOR renders a value of
    `1000000` as `1M`.
  * **Bytes**: As decimal multiple-byte units. Cortex XCOR renders a
    value of `1000000` as `1MB`.
  * **Time**: Determines the [unit of time](/overview/concepts/time-units)
    that Cortex XCOR uses to interpret a numeric value.
  * **Percent**: Interprets the value as a percentile, representing 0% to 100% in a
    range of either 0.0 to 1.0 (**Percent (0.0-1.0)**) or 0 and 100
    (**Percent (0-100)**).

    For example, Cortex XCOR renders a value of `1.0` in **Percent
    (0.0-1.0)** as `100%`, and in **Percent (0-100)** as `1%`.
* **Decimals**: Defines how many decimal places Cortex XCOR renders for
  values.
  **Default** renders decimal places only if necessary and rounds to the nearest
  value. Numeric values from `0` to `4` render the corresponding number of decimal
  places.
* **Abbreviate**: Toggles whether to abbreviate units on the Y-axis. For example, if
  enabled, Cortex XCOR renders a value of `100000000` as `100M`. You can
  toggle this setting only if you set the **Unit** to `Decimal` or `Bytes`; `Time`
  units are always abbreviated and `Percent` values don't require the toggle.
  Defaults to `true`.

### Modify a stat chart's thresholds

The **Thresholds** section in a stat chart's **Settings** tab defines values where
Cortex XCOR renders each threshold range. You can define threshold values
for stat charts as absolute numeric values.

You can enter a message in the **Base settings** section to display in the panel,
without defining a threshold. You're able to enter an independent message for each
threshold you define.

To create a new threshold value:

1. Click the plus sign (**+**) in the **Thresholds** section header.

2. In the field that displays, enter a value where you want Cortex XCOR to
   end the previous threshold range and begin the next range.

3. Optional: Click the color indicator, depicted as a colored square with text, to
   open a color selector and choose a color for the threshold.

4. Optional: Click the caret (**>**) to expand the threshold definition, and enter text
   in the **Message** field to display on the chart if the threshold is met.

   To display only the text from the **Message** field, click the
   **Show only message** toggle.

5. In the **Edit panel** interface, click **Apply** to save your changes.

6. After you've finished editing the panel, click **Save** on the dashboard to save
   your changes.

To delete a threshold value, click the caret (**>**) to expand the threshold definition,
and then click the
**<Icon icon="trash" alt="Delete icon" /> Delete** icon on its corresponding
row of the Thresholds section.

### Mark a query as a dynamic threshold

<Note>
  This feature isn't available to all Palo Alto Networks Cortex XCOR users and
  might not be visible in your app. For information about enabling this feature in your
  environment, contact [Cortex XCOR Support](/support).
</Note>

In addition to [static thresholds](#modify-a-stat-charts-thresholds) defined in the
panel settings, mark an individual query as a *dynamic threshold*. Cortex XCOR draws the
flagged query's series as a dashed reference line over every tile's
[sparkline](#modify-a-stat-charts-properties) instead of rendering it as its own stat.
The flagged series doesn't contribute to any tile's value, color, or background.
Because the reference line is drawn on the sparkline, it appears only when the stat
chart has a sparkline enabled and the threshold query returns time series data. Use
dynamic thresholds for reference values derived from a query, such as an SLO target,
an error budget limit, or a baseline measurement computed from another metric.

To mark a query as a dynamic threshold:

1. In the **Edit panel** interface, click the **Query** tab.
2. Next to the query you want to use as a threshold, click the
   **Render query as threshold** button. The query is marked as a threshold
   and its series render differently from regular data series.
3. Optional: Click the colored circle icon that appears to open a color picker
   and choose a custom threshold color.
4. Click **Apply**, and then click **Save** to save the dashboard.

To remove the threshold flag from a query, click the colored circle icon next to
the query, and then click the **<Icon icon="trash" /> Remove threshold from query**
icon in the color picker.


## Related topics

- [Visualize dashboard contents with panels](/observe/dashboards/panels.md)
- [Visualize proportional data with pie charts](/observe/dashboards/panels/pie-chart.md)
- [Visualize the status history](/observe/dashboards/panels/status-history.md)
- [Trace Explorer features overview](/investigate/querying/traces/features.md)
- [Visualize time series with charts](/observe/dashboards/panels/time-series-chart.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.