Dashboards & Visualizations

Chart not showing all the fields

shubhamnyaik
Explorer

a

Tags (1)

shubhamnyaik
Explorer

Comment is deleted

0 Karma

micahkemp
Champion

If you open that panel in search, does it have the results you expect it to have, or is it also lacking some fields?

0 Karma

shubhamnyaik
Explorer

I am posting an answer and attaching the images of the issue. there are two extraction I am using for same field.
If there is some issue with field extraction then field should not get identified in events also.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Can you provide the XML for that panel? Based on the search it looks like there should be the possible "Transaction Operations" of:

CreateIncident
UpdateIncident
GetIncident
GetIncidentWorkInfoAttachment
NotifyIncident
ManageAddress
ManageLocation
ManageAppointment
GetIncident(PAM)
GetChangeRequest
GetSIADetailed
GetNITDetailedService

It looks like you are using timechart which by default has a limit of 10 and you have 12 possible values. You can change the limit as needed and even set it to unlimited as well (http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Timechart). The reason you may not be seeing the additional values is there is no instance of them within the timerange in which your chart covers. They won't appear in the legend if an instance of that value isn't found. Try running the search over another timerange and you may see additional values appear depending on the data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...