<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Real Time Dashboard issues in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310082#M19795</link>
    <description>&lt;P&gt;can you try &lt;CODE&gt;sort- 0 Time&lt;/CODE&gt; at the end of the search?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 11:23:32 GMT</pubDate>
    <dc:creator>mayurr98</dc:creator>
    <dc:date>2018-02-23T11:23:32Z</dc:date>
    <item>
      <title>Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310080#M19793</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've built a real time dashboard but I am seeing some strange issues.&lt;BR /&gt;
So on the dashboard page itself, it displays perfectly without any issues.&lt;BR /&gt;
But when I make it my home dashboard, the time inverts and starts showing the oldest events at the top.&lt;/P&gt;

&lt;P&gt;I have no idea why this is happening.&lt;/P&gt;

&lt;P&gt;Below are some screenshots of the search and the time settings.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Dashboard view"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4440iFDA8368ED413ABAA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dashboard view" alt="Dashboard view" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Home page dashboard"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4441i780D0BC12A2E48CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Home page dashboard" alt="Home page dashboard" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 10:15:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310080#M19793</guid>
      <dc:creator>FraserC1</dc:creator>
      <dc:date>2018-02-23T10:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310081#M19794</link>
      <description>&lt;P&gt;I cannot post anymore photos, so here is the search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;severity_name=alert OR severity_level=alert OR severity_name=critical OR severity_level=critical OR severity_name=emergency OR severity_level=emergency OR severity_name=error OR severity_level=error OR severity_name=informational OR severity_level=informational OR severity_name=notification OR severity_level=notification OR severity_name=warning OR severity_level=warning |fields eventtype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The time is set to: rt-23h &amp;amp; rtnow&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 10:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310081#M19794</guid>
      <dc:creator>FraserC1</dc:creator>
      <dc:date>2018-02-23T10:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310082#M19795</link>
      <description>&lt;P&gt;can you try &lt;CODE&gt;sort- 0 Time&lt;/CODE&gt; at the end of the search?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 11:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310082#M19795</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-02-23T11:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310083#M19796</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;

&lt;P&gt;Sorry I should have said I was added sort - _time at the end of the search and it didn't make a difference.&lt;/P&gt;

&lt;P&gt;Interestingly, it seems to have sorted itself out. I'm nt sure if there is some sort of delay or something like that. I've found the custom dashboards to be fairly difficult to set up.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 11:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310083#M19796</guid>
      <dc:creator>FraserC1</dc:creator>
      <dc:date>2018-02-23T11:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310084#M19797</link>
      <description>&lt;P&gt;can you provide entire query?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 11:29:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310084#M19797</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-02-23T11:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310085#M19798</link>
      <description>&lt;P&gt;Sorry what do you mean the entire query?&lt;BR /&gt;
The only thing I'm searching is with &lt;CODE&gt;severity_name=alert OR severity_level=alert OR severity_name=critical OR severity_level=critical OR severity_name=emergency OR severity_level=emergency OR severity_name=error OR severity_level=error OR severity_name=informational OR severity_level=informational OR severity_name=notification OR severity_level=notification OR severity_name=warning OR severity_level=warning |fields eventtype&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 11:40:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310085#M19798</guid>
      <dc:creator>FraserC1</dc:creator>
      <dc:date>2018-02-23T11:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310086#M19799</link>
      <description>&lt;P&gt;try in ascending order &lt;CODE&gt;sort _time&lt;/CODE&gt;&lt;BR /&gt;
also can you try &lt;CODE&gt;| rtorder discard=t&lt;/CODE&gt; ?&lt;BR /&gt;
Also try &lt;CODE&gt;| sort -_indextime&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;let me know if any of the above works!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:23:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310086#M19799</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-02-23T12:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310087#M19800</link>
      <description>&lt;P&gt;Hi there, I tried | rtorder discard=t and it sorted it!&lt;BR /&gt;
Are you able to explain what this statement does? Or maybe there is documentation on it?&lt;/P&gt;

&lt;P&gt;Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 14:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310087#M19800</guid>
      <dc:creator>FraserC1</dc:creator>
      <dc:date>2018-02-23T14:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Dashboard issues</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310088#M19801</link>
      <description>&lt;P&gt;Yes there is a good documentation on rtorder command &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Rtorder"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Rtorder&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Accept the answer if it solves your problem!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 14:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Real-Time-Dashboard-issues/m-p/310088#M19801</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-02-23T14:53:04Z</dc:date>
    </item>
  </channel>
</rss>

