Splunk Search

How do I edit my timechart search to show all requested data?

OldManEd
Builder

I am running the following search:

index=_internal source=*metrics.log 
earliest=07/01/2015:00:00:0 
latest=08/10/2015:23:59:59 
| eval GB=kb/(1024*1024) 
| search group="per_index_thruput" 
| timechart span=1d sum(GB) by series limit=15

But when I run it, the chart data only goes back to July 13th.

alt text

Is there any way I can change the search to display all the data?

~Ed

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

The default retention period of the _internal index is 30 days (in indexes.conf on Indexers, frozenTimePeriodInSecs = 2592000). That's why the data that you see is approximately 30 days old. (there is no data to show beyond that point)

View solution in original post

somesoni2
Revered Legend

The default retention period of the _internal index is 30 days (in indexes.conf on Indexers, frozenTimePeriodInSecs = 2592000). That's why the data that you see is approximately 30 days old. (there is no data to show beyond that point)

OldManEd
Builder

Oh heck. thanks for the info.
~Ed

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...