<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reporting in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532338#M150378</link>
    <description>&lt;P&gt;Please share your current query and explain why you think timechart is not accurate.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 14:09:02 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-12-08T14:09:02Z</dc:date>
    <item>
      <title>Reporting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532287#M150366</link>
      <description>&lt;P&gt;Hi Splunkers!&lt;BR /&gt;&lt;BR /&gt;Hope you guys are doing good.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm working on a usecase where I have to show daily chart of overall results of search. I'm attaching a screenshot below.&amp;nbsp; I'm trying to show a daily count of the number in a line graph. For Example (see screenshot): I got 1350 dest statistics today and 1200 dest statistics yesteday. I want to show both on the line graph with dates.&lt;BR /&gt;by doing timechart count by dest is not giving accurate results.&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 08:01:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532287#M150366</guid>
      <dc:creator>revanthammineni</dc:creator>
      <dc:date>2020-12-08T08:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532338#M150378</link>
      <description>&lt;P&gt;Please share your current query and explain why you think timechart is not accurate.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 14:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532338#M150378</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-08T14:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532354#M150383</link>
      <description>&lt;P&gt;So I have results that I get is 1300+ for a day. I want to report a daily chart of the statistcs.&lt;BR /&gt;&lt;BR /&gt;I have included the screenshot where I tried timechart dest, But the result I'm seeing there would be spreading all the dest over the report and counting it. All I want is overall dest count for a day,&amp;nbsp; So I can show the trend.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532354#M150383</guid>
      <dc:creator>revanthammineni</dc:creator>
      <dc:date>2020-12-08T16:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532369#M150389</link>
      <description>&lt;P&gt;In general, if &lt;FONT face="courier new,courier"&gt;timechart&lt;/FONT&gt; gives unexpected results then you should blame your query rather than &lt;FONT face="courier new,courier"&gt;timechart&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;For instance, it makes little sense to use &lt;FONT face="courier new,courier"&gt;dedup&lt;/FONT&gt; before &lt;FONT face="courier new,courier"&gt;timechart count &lt;FONT face="arial,helvetica,sans-serif"&gt;because your counts will all be 1&lt;/FONT&gt;&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 18:19:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reporting/m-p/532369#M150389</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-08T18:19:42Z</dc:date>
    </item>
  </channel>
</rss>

