Splunk Search

Help with timechart

ChhayaV
Communicator

Hi,
This is my query

index=tm_idx host="audit" ID=144 | timechart count by client

its giving me chart shown below but i dont want connected lines rather i shoud be able to see just a dot/square for each login.
And also i want to see client(Admin, Moore etc) name in tool-tip instead of count
how can i do it?

Thanks and regards

alt text

0 Karma

derekarnold
Communicator

Edit your timechart visualization. Under General Options there is a dropdown box called Missing Values. Choose something other than Omit. Try Connect or Treat as Zero instead.

0 Karma

ChhayaV
Communicator

for now i am running on search bar but will be placing in dashboard panel later

0 Karma

somesoni2
Revered Legend

You are running this query in Search bar or in a dashboard panel?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...