I've come across this problem before but can't find it in the answers site.
I have a timechart within in an advanced dashboard which I'm charting a value by host and it's only showing 10 valid hosts the remaining hosts are put into this "Other" value. How do I increase the this default limit to show all the my hosts.
Thanks
Use this in your timechart command
| timechart count by usenull=f useother=f
if you put limit=0, there isn't a limit at all.
thanks
WORKD FOR ME
useother=f just leaves the 'other' field out of the results but still limits the amount of fields returned.
How do i remove other from the timechart..,How do i remove other from the timechart
The best way is to use useother=f with timechart
ex |timechart useother=f count by foobar
You can use the "limit" argument to timechart:
... | timechart count by foo limit=20
or
... | timechart count by foo limit=100
And also if/when you do want it to only show the top N values but you do NOT want it to roll up everthing else under 'OTHER', you can pass useother="f" to timechart. ( http://www.splunk.com/base/Documentation/latest/SearchReference/Timechart )