Reporting

Show report chart shows only partial time on x-axis

Path Finder

I have a search command:

.....|starttime=02/17/2011:19:20:00 endtime=02/17/2011:20:10:00 | timechart span=1s count

When I click on "Show Report" to view the graph, the x-axis only goes from 19:20 to 19:24.

Since I have a very granular span=1s I suspect I am hitting some graphing limit here.

Any suggestions on getting the graph to display the full time range??

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

The default chart will only show up to 250 or so discrete time slots. It is possible to increase this number, but only in a customized dashboard. See nick's answer here: http://answers.splunk.com/questions/543/how-do-i-change-the-default-granularity-on-a-chart/551#551