Splunk Dev

Visualization for data with large difference in values.

GenericSplunkUs
Path Finder

I can't seem to find the right terms to search to find my answer so I'm hoping someone here can help me.

I'm looking for a clean way to do the timechart command when your field values could be 5 or 500,000. With such a large difference it makes plotting them on a map useless for the smaller numbered results. I would do this to a table, but it's nice to have the timechart command show the usage over time and make it a good visual reference.

If you have another way to do this, or another command I should use that would be great.

Thanks,

Tags (1)
0 Karma
1 Solution

DalJeanis
Legend

Go ahead and use timechart. Change the visualization format for the Y axis to log.

View solution in original post

DalJeanis
Legend

Go ahead and use timechart. Change the visualization format for the Y axis to log.

GenericSplunkUs
Path Finder

Thank you, this is exactly what I wanted. I knew it had to be a simple option i just couldn't find.

0 Karma

DalJeanis
Legend

Yw. @GenericSplunkUser - if your question has been answered, then please accept the answer so the question will show as solved.

0 Karma

GenericSplunkUs
Path Finder

I thought i had done that, Thanks for the reminder.

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

Splunk Developers: Go Beyond the Dashboard with These .Conf25 Sessions

  Whether you’re building custom apps, diving into SPL2, or integrating AI and machine learning into your ...

Index This | How do you write 23 only using the number 2?

July 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...