Splunk Dev

Visualization for data with large difference in values.

GenericSplunkUs
Path Finder

I can't seem to find the right terms to search to find my answer so I'm hoping someone here can help me.

I'm looking for a clean way to do the timechart command when your field values could be 5 or 500,000. With such a large difference it makes plotting them on a map useless for the smaller numbered results. I would do this to a table, but it's nice to have the timechart command show the usage over time and make it a good visual reference.

If you have another way to do this, or another command I should use that would be great.

Thanks,

Tags (1)
0 Karma
1 Solution

DalJeanis
Legend

Go ahead and use timechart. Change the visualization format for the Y axis to log.

View solution in original post

DalJeanis
Legend

Go ahead and use timechart. Change the visualization format for the Y axis to log.

GenericSplunkUs
Path Finder

Thank you, this is exactly what I wanted. I knew it had to be a simple option i just couldn't find.

0 Karma

DalJeanis
Legend

Yw. @GenericSplunkUser - if your question has been answered, then please accept the answer so the question will show as solved.

0 Karma

GenericSplunkUs
Path Finder

I thought i had done that, Thanks for the reminder.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...