Splunk Search

Help with timechart

Communicator

Hi,
This is my query

index=tm_idx host="audit" ID=144 | timechart count by client

its giving me chart shown below but i dont want connected lines rather i shoud be able to see just a dot/square for each login.
And also i want to see client(Admin, Moore etc) name in tool-tip instead of count
how can i do it?

Thanks and regards

alt text

0 Karma

Communicator

Edit your timechart visualization. Under General Options there is a dropdown box called Missing Values. Choose something other than Omit. Try Connect or Treat as Zero instead.

0 Karma

Communicator

for now i am running on search bar but will be placing in dashboard panel later

0 Karma

SplunkTrust
SplunkTrust

You are running this query in Search bar or in a dashboard panel?

0 Karma