Splunk Search
Highlighted

OTHER option in timechart doesn't work

New Member

Hi Splunkers,

I have search like this:
index="myindex" host="myhost" | timechart span=1month latest(all_cnt) as "Number of all" by code useother=true limit=100

as a result there is all 100 values listed in timechart and legend. If I change query to:
index="myindex" host="myhost" | timechart span=1month latest(all_cnt) as "Number of all" by code useother=true limit=10

only top 10 values are represented in timechart and no "other" values are present in timechart but there is label in the legend.

Why? And how to solve this issue?

Thank you!
Dragana

0 Karma
Highlighted

Re: OTHER option in timechart doesn't work

Esteemed Legend

Try this run-anywhere search which works for me. I am sure it will work for you, too, then work backwards:

index=_* | timechart span=1m limit=10 useother=true count by sourcetype
0 Karma