Splunk Search

Chart time displayed reversed way

iceman123
Engager

Hi,

I have a search that plots a profile of a light senor over time. The log's original timestamp is saves as the time the logs were saved thus I had to extract out the actual timestamp in the log as "TIME". However, after the graph is plotted, I realized the latest data timestamp is on the left instead of the on the right. The graph is plotted laterally inverted. How should I search or change in the search to make the graph plot correctly from left to right so that the latest data is on the right?

Sample of my current graph and search syntax.
alt text

sample of the data in log.
alt text

0 Karma
1 Solution

cmerriman
Super Champion

try tacking |reverse to the end of your search

View solution in original post

cmerriman
Super Champion

try tacking |reverse to the end of your search

iceman123
Engager

Thanks cmerriman.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...