I have a search command:
.....|starttime=02/17/2011:19:20:00 endtime=02/17/2011:20:10:00 | timechart span=1s count
When I click on "Show Report" to view the graph, the x-axis only goes from 19:20 to 19:24.
Since I have a very granular span=1s I suspect I am hitting some graphing limit here.
Any suggestions on getting the graph to display the full time range??
The default chart will only show up to 250 or so discrete time slots. It is possible to increase this number, but only in a customized dashboard. See nick's answer here: http://answers.splunk.com/questions/543/how-do-i-change-the-default-granularity-on-a-chart/551#551