Splunk Search

Chart time displayed reversed way

iceman123
Engager

Hi,

I have a search that plots a profile of a light senor over time. The log's original timestamp is saves as the time the logs were saved thus I had to extract out the actual timestamp in the log as "TIME". However, after the graph is plotted, I realized the latest data timestamp is on the left instead of the on the right. The graph is plotted laterally inverted. How should I search or change in the search to make the graph plot correctly from left to right so that the latest data is on the right?

Sample of my current graph and search syntax.
alt text

sample of the data in log.
alt text

0 Karma
1 Solution

cmerriman
Super Champion

try tacking |reverse to the end of your search

View solution in original post

cmerriman
Super Champion

try tacking |reverse to the end of your search

View solution in original post

iceman123
Engager

Thanks cmerriman.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!