<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64020#M15823</link>
    <description>&lt;P&gt;for now i am running on search bar but will be placing in dashboard panel later&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2013 13:06:58 GMT</pubDate>
    <dc:creator>ChhayaV</dc:creator>
    <dc:date>2013-09-16T13:06:58Z</dc:date>
    <item>
      <title>Help with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64018#M15821</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
This is my query  &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index=tm_idx host="audit" ID=144 | timechart count by client&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;its giving me chart shown below but i dont want connected lines rather i shoud be able to see just a dot/square for each login.&lt;BR /&gt;
And also i want to see client(Admin, Moore etc) name in tool-tip instead of count&lt;BR /&gt;
how can i do it?&lt;/P&gt;

&lt;P&gt;Thanks and regards&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/splunklogin_2.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2013 11:47:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64018#M15821</guid>
      <dc:creator>ChhayaV</dc:creator>
      <dc:date>2013-09-16T11:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64019#M15822</link>
      <description>&lt;P&gt;You are running this query in Search bar or in a dashboard panel?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2013 13:05:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64019#M15822</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-09-16T13:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Help with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64020#M15823</link>
      <description>&lt;P&gt;for now i am running on search bar but will be placing in dashboard panel later&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2013 13:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64020#M15823</guid>
      <dc:creator>ChhayaV</dc:creator>
      <dc:date>2013-09-16T13:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help with timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64021#M15824</link>
      <description>&lt;P&gt;Edit your timechart visualization. Under General Options there is a dropdown box called Missing Values. Choose something other than Omit. Try Connect or Treat as Zero instead.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2013 15:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-timechart/m-p/64021#M15824</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2013-09-17T15:15:43Z</dc:date>
    </item>
  </channel>
</rss>

