<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is Splunk timechart not displaying data when last 30 days range is selected? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590279#M205509</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;I'm new to Spunk and I was working on creating a dashboard for one of my Application.&lt;/P&gt;
&lt;P&gt;Dashboard is built but when I want to populate the data for last 30 days, its giving result for only few day ( 7 to 8 days) and other days are populated as 0. When I look into that particular day, I can notice events are there.&lt;/P&gt;
&lt;P&gt;Can someone please help here?&lt;/P&gt;
&lt;P&gt;My Query format is as below,&lt;/P&gt;
&lt;P&gt;Main Query [search &amp;lt;subquery&amp;gt; ] | timechart span=1d count as total |&amp;nbsp;sort by "_time" desc&lt;/P&gt;
&lt;P&gt;My Output is as below,&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-22&lt;/TD&gt;
&lt;TD&gt;647&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-21&lt;/TD&gt;
&lt;TD&gt;988&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-20&lt;/TD&gt;
&lt;TD&gt;279&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-19&lt;/TD&gt;
&lt;TD&gt;100&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-18&lt;/TD&gt;
&lt;TD&gt;879&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-17&lt;/TD&gt;
&lt;TD&gt;1169&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-16&lt;/TD&gt;
&lt;TD&gt;15&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-15&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-14&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-13&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-12&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-11&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-10&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-09&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-08&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-07&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-06&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-05&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-04&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-03&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-02&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-01&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-02-28&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before 15th March, I see data is populated as 0 but when the same query is ran for 15th March alone I noticed events are getting populated.&lt;/P&gt;
&lt;P&gt;For eg, I selected time range as 14th March 00:00 to 15th March 24:00 for the same query, I got result as below. But this value not getting populated when last 30days time period is selected.&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-15&lt;/TD&gt;
&lt;TD&gt;587&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-14&lt;/TD&gt;
&lt;TD&gt;654&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly need help on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2022 04:09:29 GMT</pubDate>
    <dc:creator>peterfox1992</dc:creator>
    <dc:date>2022-03-23T04:09:29Z</dc:date>
    <item>
      <title>Why is Splunk timechart not displaying data when last 30 days range is selected?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590279#M205509</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;I'm new to Spunk and I was working on creating a dashboard for one of my Application.&lt;/P&gt;
&lt;P&gt;Dashboard is built but when I want to populate the data for last 30 days, its giving result for only few day ( 7 to 8 days) and other days are populated as 0. When I look into that particular day, I can notice events are there.&lt;/P&gt;
&lt;P&gt;Can someone please help here?&lt;/P&gt;
&lt;P&gt;My Query format is as below,&lt;/P&gt;
&lt;P&gt;Main Query [search &amp;lt;subquery&amp;gt; ] | timechart span=1d count as total |&amp;nbsp;sort by "_time" desc&lt;/P&gt;
&lt;P&gt;My Output is as below,&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-22&lt;/TD&gt;
&lt;TD&gt;647&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-21&lt;/TD&gt;
&lt;TD&gt;988&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-20&lt;/TD&gt;
&lt;TD&gt;279&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-19&lt;/TD&gt;
&lt;TD&gt;100&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-18&lt;/TD&gt;
&lt;TD&gt;879&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-17&lt;/TD&gt;
&lt;TD&gt;1169&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-16&lt;/TD&gt;
&lt;TD&gt;15&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-15&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-14&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-13&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-12&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-11&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-10&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-09&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-08&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-07&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-06&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-05&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-04&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-03&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-02&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-01&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-02-28&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before 15th March, I see data is populated as 0 but when the same query is ran for 15th March alone I noticed events are getting populated.&lt;/P&gt;
&lt;P&gt;For eg, I selected time range as 14th March 00:00 to 15th March 24:00 for the same query, I got result as below. But this value not getting populated when last 30days time period is selected.&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-15&lt;/TD&gt;
&lt;TD&gt;587&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022-03-14&lt;/TD&gt;
&lt;TD&gt;654&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly need help on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 04:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590279#M205509</guid>
      <dc:creator>peterfox1992</dc:creator>
      <dc:date>2022-03-23T04:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timechart not displaying data when last 30 days range is selected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590283#M205512</link>
      <description>&lt;P&gt;Perhaps your subquery is being truncated which is curtailing the results you are seeing. Does the job inspector show any warnings or other messages?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 17:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590283#M205512</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-22T17:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timechart not displaying data when last 30 days range is selected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590300#M205519</link>
      <description>&lt;P&gt;Try to run it for a week and see the result. Your queries needs optimization. If you could share your query, experts here could give you suggestions.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 19:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590300#M205519</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-03-22T19:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timechart not displaying data when last 30 days range is selected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590345#M205538</link>
      <description>&lt;P&gt;Hi, I tried to ran for a week but result populated for only 5 days and last 2 days populated as 0.&lt;/P&gt;&lt;P&gt;This is the query which I'm using. Please let me know if I'm missing something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index="foo" sourcetype="xyz" user!="abc" method=POST (url="*search*aspx*" AND code!=302 AND code!=304 AND code!=401 AND code!=403 AND code!=0) [search index="foo" method_name=pqr message="*Response Time for method pqr*" | fields uniqid]&lt;BR /&gt;| eval hour=strftime(_time,"%H") | where hour &amp;gt;=7 AND hour &amp;lt;=19&lt;BR /&gt;| timechart span=1d count(eval(time_took)) as Total ,&amp;nbsp;count(eval(time_took&amp;lt;2000)) as Success, count(eval(time_took&amp;gt;2000)) as misses | sort by "_time" desc&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 07:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590345#M205538</guid>
      <dc:creator>peterfox1992</dc:creator>
      <dc:date>2022-03-23T07:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timechart not displaying data when last 30 days range is selected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590346#M205539</link>
      <description>&lt;P&gt;Hi, Yes. Job inspector shows the below message.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The following messages were returned by the search subsystem:&lt;/P&gt;&lt;P&gt;info :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;[subsearch]: Subsearch produced 10000 results, truncating to maxout [subsearch_maxout] 10000.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 07:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590346#M205539</guid>
      <dc:creator>peterfox1992</dc:creator>
      <dc:date>2022-03-23T07:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timechart not displaying data when last 30 days range is selected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590351#M205542</link>
      <description>&lt;P&gt;So this is why you are getting different results. Essentially, the subquery is being truncated before finding uniqids prior to sometime on 16th. You could try increasing the limit (limits.conf) or you may need to refactor your search to avoid this truncation.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 08:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590351#M205542</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-23T08:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timechart not displaying data when last 30 days range is selected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590524#M205597</link>
      <description>&lt;P&gt;If you run below query for last 30 days, how many records do you get?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="foo" method_name=pqr message="*Response Time for method pqr*" | stats count by uniqid&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, give this a try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index="foo" sourcetype="xyz" user!="abc" method=POST (url="*search*aspx*" AND code!=302 AND code!=304 AND code!=401 AND code!=403 AND code!=0)) OR ( index="foo" method_name=pqr message="*Response Time for method pqr*" )
| fields _time uniqid time_took
| eval hour=strftime(_time,"%H") | where NOT (method=POST AND hour &amp;lt;7 AND hour &amp;gt;19)
| bucket span=1d _time | stats dc(method) as methods count(time_took) as Total count(eval(time_took&amp;lt;2000)) as Success, count(eval(time_took&amp;gt;2000)) as misses by _time uniqid | where methods=2
| timechart span=1d sum(Total) as Total , sum(Success) as Success, sum(misses) as misses | sort by "_time" desc&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 23 Mar 2022 19:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Splunk-timechart-not-displaying-data-when-last-30-days/m-p/590524#M205597</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-03-23T19:04:46Z</dc:date>
    </item>
  </channel>
</rss>

