I have a CSV dataset with 2 colomns (_time , temperature) but when i import the dataset in Splunk to do a visualization of the dataset, Splunk plot the dataset with the temperature as the X value and the time as a Y value. How can I change the two columns?
I tried to modify directly the CSV file but doesn't change anything.
I see a warning on your screenshot top-left stating that _time should be UNIX time. I think your CSV timestamps are not epoc. Can you please change the search like below;
| inputcsv dataset.csv | eval _time=strptime(_time,"%Y-%m-%d %H:%M") | table _time temperature
The instructions at https://docs.splunk.com/Documentation/MLApp/5.2.1/User/FTSExperiment#Assistant_workflow say to specify a Period. Have you tried that?