<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A great Charting Problem! in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36158#M8037</link>
    <description>&lt;P&gt;In simple XML you can increase the number of points in a chart by including.&lt;/P&gt;

&lt;P&gt;5000&lt;/P&gt;</description>
    <pubDate>Thu, 27 Mar 2014 18:07:57 GMT</pubDate>
    <dc:creator>arthurjspencer</dc:creator>
    <dc:date>2014-03-27T18:07:57Z</dc:date>
    <item>
      <title>A great Charting Problem!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36156#M8035</link>
      <description>&lt;P&gt;I do not understand why Im currently having this problem, I have never had this problem before when creating charts with splunk!&lt;/P&gt;

&lt;P&gt;The problem is when using the follwing search to create a chart with span=5m within a Timestamp of a whole Month:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;index="INDEX" GET*  | timechart bins=50000 span=5m count&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I only get three days, and the rest of the days seem to shift to the right of the chart and disappear as it loads!&lt;/P&gt;

&lt;P&gt;This is a very weird behaviour, I dont understand why its behaving like this, the flashtime search works fine with all the results for that month, but when creating the chart it doesn't seem to work normally&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2011 01:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36156#M8035</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2011-12-16T01:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: A great Charting Problem!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36157#M8036</link>
      <description>&lt;P&gt;The maximum points of x-axis is 1000 points in splunk chart. Therefore you will not be able to create monthly report with such a small time span like 5m. Can  you change time span to span=1d ? Then you will see whole chart in the month. You will need to adjust them to what you want to see.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2011 01:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36157#M8036</guid>
      <dc:creator>Takajian</dc:creator>
      <dc:date>2011-12-16T01:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: A great Charting Problem!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36158#M8037</link>
      <description>&lt;P&gt;In simple XML you can increase the number of points in a chart by including.&lt;/P&gt;

&lt;P&gt;5000&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 18:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/A-great-Charting-Problem/m-p/36158#M8037</guid>
      <dc:creator>arthurjspencer</dc:creator>
      <dc:date>2014-03-27T18:07:57Z</dc:date>
    </item>
  </channel>
</rss>

