Reporting

How can I show results from Other?

rtmcdonald
Explorer

When I create a chart it takes the bottom results and creates a category called Other. I want to show the results that are being lumped into other. How can I do that?

Thanks,

-Ryan

Tags (1)
0 Karma

ftk
Motivator

Since you indicated that christopherutz's answer did indeed answer your question, please accept his answer by clicking the green checkmark next to it so this question can be closed out. Thanks

0 Karma

christopherutz
Path Finder

Try

... | chart limit=0 ...

This is how I eliminate the aggregation of classes into an "other" category with timechart.

rtmcdonald
Explorer

That worked! Thanks....

0 Karma

christopherutz
Path Finder

Note. There was at one point (possibly still) a bug when using limit=0. If you run into an issue with an extra column check out this question.

http://answers.splunk.com/questions/4638/timechart-and-chart-display-buggy-column-count-when-using-l...

0 Karma

jhodges
Engager

add the useother paramter:

chart useother=0

0 Karma

rtmcdonald
Explorer

It looks like that just hides the column

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...