Splunk Search

Chart time displayed reversed way

iceman123
Engager

Hi,

I have a search that plots a profile of a light senor over time. The log's original timestamp is saves as the time the logs were saved thus I had to extract out the actual timestamp in the log as "TIME". However, after the graph is plotted, I realized the latest data timestamp is on the left instead of the on the right. The graph is plotted laterally inverted. How should I search or change in the search to make the graph plot correctly from left to right so that the latest data is on the right?

Sample of my current graph and search syntax.
alt text

sample of the data in log.
alt text

0 Karma
1 Solution

cmerriman
Super Champion

try tacking |reverse to the end of your search

View solution in original post

cmerriman
Super Champion

try tacking |reverse to the end of your search

iceman123
Engager

Thanks cmerriman.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...