Dashboards & Visualizations

How do I align multiple reports in a dashboard so that the time markers are aligned vertically?

dphung
Explorer

I have multiple reports with the same bucket span and time range collated together in a dashboard. Is there a way to have the time markers aligned vertically?

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You need to make the charts the same width (obviously) and make sure the parts to the left and right of the charts are the same width. Specifically, either move the legend to the top/bottom or make sure the fields are the same length or remove the legends and make sure the Y-axis scales are the same length. Then you should see the markers align on their own.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Are you searching over all time?

Note, I've had some issues surrounding empty buckets gone missing at the beginning or end of a timechart in the past, not sure if they still exist. If you're not searching over all time and not setting fixedrange=f but still don't get buckets with count=0 at the beginning or end that would fall within the timerange but don't have any data in them you should file a case that timechart is a bit broken here.

Have you considered a search for all your sources and a count by source to get one chart?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could upload your screenshot somewhere (e.g. imgur.com) and post the URL.

0 Karma

dphung
Explorer

Here's an example: https://dl.dropboxusercontent.com/spa/jq9rmutima7jf7v/z8r5huo1.png

Notice how the alignment depends on the number of events at the beginning of the time range. I tried forcing fixedrange=True and using per_day(), but none of those gives me an absolute time range.

0 Karma

dphung
Explorer

That's not quite enough. I've removed the legends and the panels on the dashboard are aligned but the problem seems to be the time markers (and report) adjusts the view and time markers depending on the data. I just created an example where (on my macbook) I added the following reports to a dashboard (both the same time range of 1 week):

source=/var/log/system.log | timechart span="1h" count
source=/var/log/commerce.log | timechart span='1h" count

and the time is not aligned. I tried to attach a screenshot but I don't have enough karma. What I really want is to be able to control the X-axis in the report controls, but option isn't provided.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...