Dashboards & Visualizations

This visualization is configured to display a maximum of 1000 results per series

wcleong
New Member

hi, I have following problem when creating a scatter chart, the search returned >1000 entries, how can I increase the maximum results of the graph??

I got this message.
This visualization is configured to display a maximum of 1000 results per series

I have modified JSChart.conf but it seems to be not working.

Tags (2)
0 Karma

ers81239
Engager

I know this question is ancient, but I was just dealing with this problem trying to show a line graph for the stats reported by the TA for Unix. I was able to solve the 1000 results per series issue and also get better control over which stats are displayed by explicitly using a timechart command. So my search string went from:

`os_index` `cpu_sourcetype` all

to:

`os_index` `cpu_sourcetype` all  | timechart avg(pctIowait), avg(pctSystem), avg(pctUser)

I think that in this case, the timechart command does the aggregation by time which winds up sending less data points to the graph itself.

0 Karma

yannK
Splunk Employee
Splunk Employee

The setting is looking at charting.chart.data.count at the maximum limit of events to retrieve, and the default is 1000.
see http://docs.splunk.com/Documentation/Splunk/6.2.1/AdvancedDev/AdvChartingConfig-LayoutData#Timeline_...

Can you try adding this parameter with a higher limit and retry ?

`< option name="charting.data.count" >9999</ option >

`this works on simple XML

jtrucks
Splunk Employee
Splunk Employee

Does this help?

http://answers.splunk.com/answers/10349/chart-only-showing-1000-events

--
Jesse Trucks
Minister of Magic
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You're likely better off modifying your search to yield less than 1000 results.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...