<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timechart with large split by gives&amp;quot; Your search generated too much data for the current visualization configuration.&amp;quot; Is it truncating stats or chart or both? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162854#M46234</link>
    <description>&lt;P&gt;When running a search against a weblog, and attempting to "|timechart span=1h limit=0 count by queryname" for 24hrs, I get the " Your search generated too much data for the current visualization configuration."&lt;/P&gt;

&lt;P&gt;Is it just truncating the graph, or the statistics table as well?&lt;/P&gt;</description>
    <pubDate>Tue, 13 May 2014 22:26:01 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2014-05-13T22:26:01Z</dc:date>
    <item>
      <title>Timechart with large split by gives" Your search generated too much data for the current visualization configuration." Is it truncating stats or chart or both?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162854#M46234</link>
      <description>&lt;P&gt;When running a search against a weblog, and attempting to "|timechart span=1h limit=0 count by queryname" for 24hrs, I get the " Your search generated too much data for the current visualization configuration."&lt;/P&gt;

&lt;P&gt;Is it just truncating the graph, or the statistics table as well?&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2014 22:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162854#M46234</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2014-05-13T22:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Timechart with large split by gives" Your search generated too much data for the current visualization configuration." Is it truncating stats or chart or both?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162855#M46235</link>
      <description>&lt;P&gt;Hi mikelanghorst,&lt;/P&gt;

&lt;P&gt;according to the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.4/AdvancedDev/CustomChartingConfig-JSChart"&gt;docs&lt;/A&gt; this message is from the JSChart Module and related to the object rendering limit in the chart library.  &lt;/P&gt;

&lt;P&gt;running this test search on my development box &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal | timechart span=10sec count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;returns about 4700 events in the statistic table but brings the message &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached. 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;on the report graph.&lt;BR /&gt;
So from my understanding this message is completely related to the chart and not effects the statistic table.&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 06:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162855#M46235</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-05-14T06:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Timechart with large split by gives" Your search generated too much data for the current visualization configuration." Is it truncating stats or chart or both?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162856#M46236</link>
      <description>&lt;P&gt;Have you opened a case with Splunk for this? This is a hard limit which we have an enhancement request ticket open, more customers requesting this to be raised should push Splunk to fix this.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 17:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timechart-with-large-split-by-gives-quot-Your-search-generated/m-p/162856#M46236</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2016-09-15T17:34:25Z</dc:date>
    </item>
  </channel>
</rss>

