Splunk Search

Show only every N days in line chart where time is X axis?

msarro
Builder

Below you will find a line chart which I've created. It uses a linear regression to predict what values are going to be at N days in the future based on recent trends. However the downside is, splunk tries to label every single day along the X axis which creates a number of "..." labels which really aren't helpful. It would be better if I could have it only show a label every N days.
Any idea on how to approach this would be great.

alt text

Tags (2)
0 Karma
1 Solution

tfletcher_splun
Splunk Employee
Splunk Employee

JSChart is reading the fields in your search results to do this. I am guessing that you are not using timechart to plot this data which is why that metadata field it is looking for is absent. You can hack it in by ending your search with an eval or you can use a timechart command with a span declaration.

for the hack, the integer represents the jschart's x-axis span:

| eval _span=60

View solution in original post

tfletcher_splun
Splunk Employee
Splunk Employee

JSChart is reading the fields in your search results to do this. I am guessing that you are not using timechart to plot this data which is why that metadata field it is looking for is absent. You can hack it in by ending your search with an eval or you can use a timechart command with a span declaration.

for the hack, the integer represents the jschart's x-axis span:

| eval _span=60

msarro
Builder

This worked really well, thank you!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...