Reporting

Show report chart shows only partial time on x-axis

nbharadwaj
Path Finder

I have a search command:

.....|starttime=02/17/2011:19:20:00 endtime=02/17/2011:20:10:00 | timechart span=1s count

When I click on "Show Report" to view the graph, the x-axis only goes from 19:20 to 19:24.

Since I have a very granular span=1s I suspect I am hitting some graphing limit here.

Any suggestions on getting the graph to display the full time range??

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The default chart will only show up to 250 or so discrete time slots. It is possible to increase this number, but only in a customized dashboard. See nick's answer here: http://answers.splunk.com/questions/543/how-do-i-change-the-default-granularity-on-a-chart/551#551

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...