Archive
Highlighted

Chart not showing all the fields

Explorer

a

Tags (1)
Highlighted

Re: Chart not showing all the fields

SplunkTrust
SplunkTrust

Can you provide the XML for that panel? Based on the search it looks like there should be the possible "Transaction Operations" of:

CreateIncident
UpdateIncident
GetIncident
GetIncidentWorkInfoAttachment
NotifyIncident
ManageAddress
ManageLocation
ManageAppointment
GetIncident(PAM)
GetChangeRequest
GetSIADetailed
GetNITDetailedService

It looks like you are using timechart which by default has a limit of 10 and you have 12 possible values. You can change the limit as needed and even set it to unlimited as well (http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Timechart). The reason you may not be seeing the additional values is there is no instance of them within the timerange in which your chart covers. They won't appear in the legend if an instance of that value isn't found. Try running the search over another timerange and you may see additional values appear depending on the data.

0 Karma
Highlighted

Re: Chart not showing all the fields

Champion

If you open that panel in search, does it have the results you expect it to have, or is it also lacking some fields?

0 Karma
Highlighted

Re: Chart not showing all the fields

Explorer

I am posting an answer and attaching the images of the issue. there are two extraction I am using for same field.
If there is some issue with field extraction then field should not get identified in events also.

0 Karma
Highlighted

Re: Chart not showing all the fields

Explorer

Comment is deleted

0 Karma