Splunk Search

Chart time displayed reversed way

iceman123
Engager

Hi,

I have a search that plots a profile of a light senor over time. The log's original timestamp is saves as the time the logs were saved thus I had to extract out the actual timestamp in the log as "TIME". However, after the graph is plotted, I realized the latest data timestamp is on the left instead of the on the right. The graph is plotted laterally inverted. How should I search or change in the search to make the graph plot correctly from left to right so that the latest data is on the right?

Sample of my current graph and search syntax.
alt text

sample of the data in log.
alt text

0 Karma
1 Solution

cmerriman
Super Champion

try tacking |reverse to the end of your search

View solution in original post

cmerriman
Super Champion

try tacking |reverse to the end of your search

iceman123
Engager

Thanks cmerriman.

0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...