Dashboards & Visualizations

Chart not showing all the fields

shubhamnyaik
Explorer

a

Tags (1)

shubhamnyaik
Explorer

Comment is deleted

0 Karma

micahkemp
Champion

If you open that panel in search, does it have the results you expect it to have, or is it also lacking some fields?

0 Karma

shubhamnyaik
Explorer

I am posting an answer and attaching the images of the issue. there are two extraction I am using for same field.
If there is some issue with field extraction then field should not get identified in events also.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Can you provide the XML for that panel? Based on the search it looks like there should be the possible "Transaction Operations" of:

CreateIncident
UpdateIncident
GetIncident
GetIncidentWorkInfoAttachment
NotifyIncident
ManageAddress
ManageLocation
ManageAppointment
GetIncident(PAM)
GetChangeRequest
GetSIADetailed
GetNITDetailedService

It looks like you are using timechart which by default has a limit of 10 and you have 12 possible values. You can change the limit as needed and even set it to unlimited as well (http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Timechart). The reason you may not be seeing the additional values is there is no instance of them within the timerange in which your chart covers. They won't appear in the legend if an instance of that value isn't found. Try running the search over another timerange and you may see additional values appear depending on the data.

0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...