Splunk Search

Display chart only within Time range where there data exists

Dark_Ichigo
Builder

I want to display a chart that automatically crops that whole chart to where there is data and not display any empty before or after time ranges where there is no data at all, how can this be done?

Please let me know if more information is required.

1 Solution

lguinn2
Legend

In your timechart command, use the option

fixedrange=false

for example

yoursearchhere
| timechart fixedrange=false count

then the timechart X-axis will be cropped to only the timerange that includes valid data.

Documentation for timechart command

View solution in original post

lguinn2
Legend

In your timechart command, use the option

fixedrange=false

for example

yoursearchhere
| timechart fixedrange=false count

then the timechart X-axis will be cropped to only the timerange that includes valid data.

Documentation for timechart command

sansay
Contributor

That worked perfectly for my purpose.
I combined data from 2 different days, and shifted the date of the first day so that timechart would show them at the same times, but I ended with an empty set. This solved my problem. Thank you very much!

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...