Reporting

Show report chart shows only partial time on x-axis

nbharadwaj
Path Finder

I have a search command:

.....|starttime=02/17/2011:19:20:00 endtime=02/17/2011:20:10:00 | timechart span=1s count

When I click on "Show Report" to view the graph, the x-axis only goes from 19:20 to 19:24.

Since I have a very granular span=1s I suspect I am hitting some graphing limit here.

Any suggestions on getting the graph to display the full time range??

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The default chart will only show up to 250 or so discrete time slots. It is possible to increase this number, but only in a customized dashboard. See nick's answer here: http://answers.splunk.com/questions/543/how-do-i-change-the-default-granularity-on-a-chart/551#551

Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...