Splunk Search

Display chart only within Time range where there data exists

Dark_Ichigo
Builder

I want to display a chart that automatically crops that whole chart to where there is data and not display any empty before or after time ranges where there is no data at all, how can this be done?

Please let me know if more information is required.

1 Solution

lguinn2
Legend

In your timechart command, use the option

fixedrange=false

for example

yoursearchhere
| timechart fixedrange=false count

then the timechart X-axis will be cropped to only the timerange that includes valid data.

Documentation for timechart command

View solution in original post

lguinn2
Legend

In your timechart command, use the option

fixedrange=false

for example

yoursearchhere
| timechart fixedrange=false count

then the timechart X-axis will be cropped to only the timerange that includes valid data.

Documentation for timechart command

sansay
Contributor

That worked perfectly for my purpose.
I combined data from 2 different days, and shifted the date of the first day so that timechart would show them at the same times, but I ended with an empty set. This solved my problem. Thank you very much!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...