I have a search with timechart, If I use the VIS column chart I only see the mondays as date on the axis. Is it possible to show every day per column?
index=test host=test* |my search | eval date=strptime(date,"%A%m/%d/%Y") | timechart span=1d count
Try something like this. You have to manually select the column chart and format the X-Axis Label to rotate vertically.
<base_search>
| timechart span=1d count
| eval date=strftime(_time, "%Y-%m-%d")
| table date count
I believe Splunk manages that automatically based on the width of the columns. Fewer columns can be wider, allowing for more labels. You can try overriding that using this in your dashboard.
<option name="charting.axisLabelsX.majorLabelVisibility">show</option>