Splunk Dev

Visualization for data with large difference in values.

GenericSplunkUs
Path Finder

I can't seem to find the right terms to search to find my answer so I'm hoping someone here can help me.

I'm looking for a clean way to do the timechart command when your field values could be 5 or 500,000. With such a large difference it makes plotting them on a map useless for the smaller numbered results. I would do this to a table, but it's nice to have the timechart command show the usage over time and make it a good visual reference.

If you have another way to do this, or another command I should use that would be great.

Thanks,

Tags (1)
0 Karma
1 Solution

DalJeanis
Legend

Go ahead and use timechart. Change the visualization format for the Y axis to log.

View solution in original post

DalJeanis
Legend

Go ahead and use timechart. Change the visualization format for the Y axis to log.

GenericSplunkUs
Path Finder

Thank you, this is exactly what I wanted. I knew it had to be a simple option i just couldn't find.

0 Karma

DalJeanis
Legend

Yw. @GenericSplunkUser - if your question has been answered, then please accept the answer so the question will show as solved.

0 Karma

GenericSplunkUs
Path Finder

I thought i had done that, Thanks for the reminder.

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...