Dashboards & Visualizations

Is it possible to achieve a column chart with timechart showing days in every column?

Mike6960
Path Finder

I have a search with timechart, If I use the VIS column chart I only see the mondays as date on the axis. Is it possible to show every day per column?

 

index=test host=test* |my  search  | eval date=strptime(date,"%A%m/%d/%Y") | timechart span=1d count

Mike6960_0-1668077437140.png

 

Labels (1)
0 Karma

johnhuang
Motivator

Try something like this. You have to manually select the column chart and format the X-Axis Label to rotate vertically.

<base_search>
| timechart span=1d count
| eval date=strftime(_time, "%Y-%m-%d")
| table date count

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe Splunk manages that automatically based on the width of the columns.  Fewer columns can be wider, allowing for more labels.  You can try overriding that using this in your dashboard.

 

<option name="charting.axisLabelsX.majorLabelVisibility">show</option>

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...