<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Graph sizing in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445526#M40750</link>
    <description>&lt;P&gt;Does the visualization &lt;CODE&gt;connect&lt;/CODE&gt; help? &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;option name="charting.chart.nullValueMode"&amp;gt;connect&amp;lt;/option&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Oct 2018 10:55:14 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2018-10-25T10:55:14Z</dc:date>
    <item>
      <title>Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445525#M40749</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
we get Data from a Windows Server, i have change the interval from every 1minute to 10 minutes.&lt;BR /&gt;
Thats enough to get valid informations.&lt;/P&gt;

&lt;P&gt;Now we have a Problem with the graph, there are some gaps in it.&lt;BR /&gt;
At the moment the X Xis is set to minutes.&lt;/P&gt;

&lt;P&gt;is it possible to fill out the gaps?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5988iDE1CF8EC9494BF88/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 09:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445525#M40749</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-25T09:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445526#M40750</link>
      <description>&lt;P&gt;Does the visualization &lt;CODE&gt;connect&lt;/CODE&gt; help? &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;option name="charting.chart.nullValueMode"&amp;gt;connect&amp;lt;/option&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 10:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445526#M40750</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-10-25T10:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445527#M40751</link>
      <description>&lt;P&gt;Where can i insert this Option? in the search directly=?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 11:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445527#M40751</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-25T11:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445528#M40752</link>
      <description>&lt;P&gt;Ok i have found the option to display the source. The connect option dosent help&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 11:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445528#M40752</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-25T11:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445529#M40753</link>
      <description>&lt;P&gt;Can you share the search that generates this graph? You may need to tweak the span setting on the timechart command, to match the frequency at which the data comes in.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 07:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445529#M40753</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-10-26T07:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445530#M40754</link>
      <description>&lt;P&gt;Hi Frank,&lt;BR /&gt;
this is the search: index="xd" SessionState="Active" &lt;BR /&gt;
Is very simple, i will get the active Session in CITRIX. I have installed the CITRIX 7 Template in Splunk.&lt;BR /&gt;
I have modifyed the interval on the Splunk Forwarder to get every 10 Minutes the active Sessions.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445530#M40754</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-26T08:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445531#M40755</link>
      <description>&lt;P&gt;Hi Frank,&lt;BR /&gt;
this is my search: index="xd" SessionState="Active" &lt;BR /&gt;
I will get the Active Sessions in CITRIX. I have installed the CITRIX 7 Template.&lt;BR /&gt;
The Splunk Forwarder send every 10 Minutes new logs. &lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445531#M40755</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-26T08:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445532#M40756</link>
      <description>&lt;P&gt;Just that search alone will not get you that graph. Don't you have a timechart in there somewhere?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445532#M40756</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-10-26T08:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445533#M40757</link>
      <description>&lt;P&gt;Maybe this help you:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;title&amp;gt;XenApp Active Sessions&amp;lt;/title&amp;gt;
  &amp;lt;chart&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;| pivot XenAppSessions RootObject count(RootObject) AS Sessions SPLITROW _time AS _time PERIOD minute SORT 0 _time ROWSUMMARY 0 COLSUMMARY 0 SHOWOTHER 1&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.maximumNumber"&amp;gt;80&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;connect&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.overlayFields"&amp;gt;AvgOverall&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.mode"&amp;gt;standard&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.lineWidth"&amp;gt;2&amp;lt;/option&amp;gt;
    &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="trellis.size"&amp;gt;large&amp;lt;/option&amp;gt;
  &amp;lt;/chart&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445533#M40757</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-26T08:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445534#M40758</link>
      <description>&lt;P&gt;Guess it is because of the &lt;CODE&gt;PERIOD minute&lt;/CODE&gt; part. So the results get bucketed per minute, since you only have data once every 10 minutes, you have empty buckets, resulting in those gaps in the graph.&lt;/P&gt;

&lt;P&gt;Changing it to &lt;CODE&gt;PERIOD hour&lt;/CODE&gt; probably gets rid of the gaps, but then you'll loose some detail I think (not very familiar with pivot).&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:42:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445534#M40758</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-10-26T08:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445535#M40759</link>
      <description>&lt;P&gt;It is a bit strange, when i set to PERIOD minute, i get the correct Session number. When i change to PERIOD hour, i get strange numbers. Normal Numbers are arround 200 with PERIOD minute, with PERIOD hour i get 800 or more.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:46:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445535#M40759</guid>
      <dc:creator>TheOnlyOne</dc:creator>
      <dc:date>2018-10-26T08:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Graph sizing</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445536#M40760</link>
      <description>&lt;P&gt;I guess that is because 1h contains multiple imports and it does a count. So you probably get the sum of the sessioncounts from the various inputs?&lt;/P&gt;

&lt;P&gt;Not sure if there is any way to make this work properly when your import frequency does not align with the pivot PERIOD. Maybe someone with more pivot experience can say something on that.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 09:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Graph-sizing/m-p/445536#M40760</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-10-26T09:18:27Z</dc:date>
    </item>
  </channel>
</rss>

