Deployment Architecture

Why does Timechart only shows Nulls on Dashboard?

P_Orourke
Loves-to-Learn Lots

Hey,

I am using a timechart on my dashboard, but it only shows NULL values. When I run the same search on search console, it shows all values as expected. What is the issue?

Here is how it looks when I run it in the Search:
Timecaht_Normal_In_Search.PNG

Here is how the timechart looks in the dashboard:
Timecaht_Bad_In_Dashbaord.PNG

Here is the XML code for the dashbaord:
Timecaht_Bad_XML.PNG


Can you please help?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The base query is not transforming so no fields are available for post-processing.  Try adding | fields * to the base.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros?Join  Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...