I have a requirement in which I don't want to display the last bucket of data in the timechart.
Example: The bucket timespan is 5m. If I open my Dashboard at 11:02 am, the last bucket will contain data for only 2 minutes. I don't want to display this data in timechart.
Is there anyway to remove this last bucket data?
Tack this onto your existing search:
... | eventstats max(_time) AS maxTime | where _time < maxTime | fields - maxTime
I tested it before I posted; it DEFINITELY works. If it is not working for you, then I will need to see your actual search which must be doing something unusual.
Thanks, @woodcock. Here's a variation to drop both first and last buckets.
| eventstats min(_time) as minTime max(_time) as maxTime | where _time > minTime AND _time < maxTime | fields - minTime, maxTime
If the goal is not to show partial/incomplete buckets in you timechart, this option should work for your use case, partial=false.
| timechart partial=false