<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timechart after sort display in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693478#M235938</link>
    <description>&lt;P&gt;Hey,&lt;BR /&gt;Iv'e noticed some wierd behviour that is making me suspect the relaibility of my queries so I'm really looking for an explanation, I was making some searches and displaying them on a timechart, for some reason the timechart looks completly different when I sort the fields befor.&lt;BR /&gt;&lt;BR /&gt;this is the basic search and it's results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count WHERE case=test responseCode=200 requestStatus!=legal by clientIp _time span=1h| timechart sum(count) span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hod152_2-1721131756532.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31791i3C5A99D6B320EC9A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hod152_2-1721131756532.png" alt="Hod152_2-1721131756532.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After sorting clientIp field this is how the graph looks like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count WHERE case=test  responseCode=200 requestStatus!=legal by clientIp _time span=1h| sort -clientIp |timechart sum(count) span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hod152_1-1721131709287.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31790iF539087E6BCCAFD3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hod152_1-1721131709287.png" alt="Hod152_1-1721131709287.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count WHERE case=test responseCode=200 requestStatus!=legal by clientIp _time span=1h| sort +clientIp |timechart sum(count) span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hod152_3-1721132009680.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31792iEBF058491342ACBF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hod152_3-1721132009680.png" alt="Hod152_3-1721132009680.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Note that the count is decreased on the sorted search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;What can explain that behaviour? Which chart should I relay on? Is that a feature of sorting?&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jul 2024 12:17:40 GMT</pubDate>
    <dc:creator>Hod152</dc:creator>
    <dc:date>2024-07-16T12:17:40Z</dc:date>
    <item>
      <title>Timechart after sort display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693478#M235938</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;Iv'e noticed some wierd behviour that is making me suspect the relaibility of my queries so I'm really looking for an explanation, I was making some searches and displaying them on a timechart, for some reason the timechart looks completly different when I sort the fields befor.&lt;BR /&gt;&lt;BR /&gt;this is the basic search and it's results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count WHERE case=test responseCode=200 requestStatus!=legal by clientIp _time span=1h| timechart sum(count) span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hod152_2-1721131756532.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31791i3C5A99D6B320EC9A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hod152_2-1721131756532.png" alt="Hod152_2-1721131756532.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After sorting clientIp field this is how the graph looks like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count WHERE case=test  responseCode=200 requestStatus!=legal by clientIp _time span=1h| sort -clientIp |timechart sum(count) span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hod152_1-1721131709287.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31790iF539087E6BCCAFD3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hod152_1-1721131709287.png" alt="Hod152_1-1721131709287.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count WHERE case=test responseCode=200 requestStatus!=legal by clientIp _time span=1h| sort +clientIp |timechart sum(count) span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hod152_3-1721132009680.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31792iEBF058491342ACBF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hod152_3-1721132009680.png" alt="Hod152_3-1721132009680.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Note that the count is decreased on the sorted search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;What can explain that behaviour? Which chart should I relay on? Is that a feature of sorting?&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 12:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693478#M235938</guid>
      <dc:creator>Hod152</dc:creator>
      <dc:date>2024-07-16T12:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Timechart after sort display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693481#M235939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258182"&gt;@Hod152&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;why you did this?&lt;/P&gt;&lt;P&gt;if you have tstats BY _time, you already have the timechart:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats 
     count 
     WHERE case=test  responseCode=200 requestStatus!=legal 
     BY clientIp _time span=1h&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, it's always better to indicate the indexes to use in the search, to have more performant searces&amp;nbsp; and avoid default search path issues.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 12:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693481#M235939</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-07-16T12:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Timechart after sort display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693485#M235940</link>
      <description>&lt;P&gt;sort truncates at 10k values - try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| sort 0 -clientip&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 16 Jul 2024 13:03:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693485#M235940</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-16T13:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Timechart after sort display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693595#M235968</link>
      <description>&lt;P&gt;It just suited my work sequence...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 10:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693595#M235968</guid>
      <dc:creator>Hod152</dc:creator>
      <dc:date>2024-07-17T10:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Timechart after sort display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693601#M235971</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 11:00:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-after-sort-display/m-p/693601#M235971</guid>
      <dc:creator>Hod152</dc:creator>
      <dc:date>2024-07-17T11:00:58Z</dc:date>
    </item>
  </channel>
</rss>

