Is it possible for Splunk to show ALL days on the x-axis for a timechart? I have a search which returns data for every single day for the last month, but the x-axis is only filled with labels for the start of each week.
Ideally i would like it to show me, Mon, Tue, Wed etc...
Also, i am using | timechart count
If its on a dashboard you could edit the xml to add some options :
<option name="charting.chart">line</option> <option name="charting.axisLabelsX.majorLabelVisibility">hide</option> <option name="charting.axisLabelsX.minorLabelVisibility">show</option>
This'll hide the start of week labels on the X axis, and enable the daily (minorLabels)
Its a bit cramped though.
All the axis/chart options are documented here