Dashboards & Visualizations

Sparkline maximum data points?

MonkeyK
Builder

I recently noticed that my sparklines may appear to lose data when I make the resolution too fine. For example over the course of a days data, sparkline(sum(count),1h) as countTrend1h will represent the trend OK, but sparkline(sum(count),5m) as countTrend5m will show only part of the results. I think that this is because at a resolution of 1hour, I have only 24 datapoints, while a resolution of 5m has 288.

What is the maximum number of datapoints that Splunk can reasonable handler in a sparkline? Also, is there a way to deal with it if I inadvertently exceed that number of data points? alt text

0 Karma
1 Solution

gergelybata
Explorer

Sparklines can have 101 data points maximum.
In fact, sparkline generates a multivalue field with a special "header", something like this:

##__SPARKLINE__##,113,322,275,334,314,284,...

So you can use every mv.... command on these fields, e.g. mvcount(countTrend5m)

View solution in original post

lstewart_splunk
Splunk Employee
Splunk Employee

You can generate sparkline charts with the tstats command only if you specify the _time field in the BY clause and use the stats command to generate the actual sparkline.

For example:

| tstats count from datamodel=Authentication.Authentication BY _time, Authentication.src span=1h | stats sparkline(sum(count),1h) AS sparkline, sum(count) as count BY Authentication.src

Also, I don't know if the limit suggested is accurate. When you run the following command, you get many more data points than 101 which are charted:

index=_internal | chart sparkline count by sourcetype
0 Karma

gergelybata
Explorer

Sparklines can have 101 data points maximum.
In fact, sparkline generates a multivalue field with a special "header", something like this:

##__SPARKLINE__##,113,322,275,334,314,284,...

So you can use every mv.... command on these fields, e.g. mvcount(countTrend5m)

Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...