Splunk Search

Timechart flickering issue not pointing to data points properly on mouse over ?

pgadhari
Builder

I am facing issues when I am trying to mouse over on the timechart to see the exact values on the graph. I am selecting "Last 30 days", there is one spike which shows up in the graph, but when I try to see the exact value of that point using mouse over, it is not pointing to that spike properly and keeps on flickering if I move the pointer there ? Any one has seen this issue before ? Please help how it can be resolved. This is sort of a flickering issue on the timechart during mouse over ?

My timechart is plotting data points with a span of 5 mins for last 30 days.

Also, second problem, is for last 30 days, it is adding shade of colors, so users are thinking that there are 3 colors in the timechart for IN and OUT, but for IN it is adding shade of blue color ? is it possible to disable that ?

I have attached the image before hover and after hover.

First Image - shows the high point and the shade of blue color (light blue) added to the graph ?
Second Image - while trying to point the high point, mouse over is not going to that point properly to see the highest value ?

alt text

alt text

0 Karma
1 Solution

niketnilay
Legend

@pgadhari can you try the UI edit and Legend seriesCompare option and see if value shows up when you scroll though the series?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketnilay
Legend

@pgadhari can you try the UI edit and Legend seriesCompare option and see if value shows up when you scroll though the series?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

pgadhari
Builder

I tried doing the series compare but it is not showing the values on mouse-over now ? Just showing the time on the series ?

Below is the link for the image :

alt text

0 Karma

pgadhari
Builder

https://imgur.com/a/flTEFOX

somehow it is not showing the link. Hence, putting it here.

0 Karma

niketnilay
Legend

Hey Series Compare shows value on right side next to the Legend names.
Refer to one of my older answer with CSS overridd to make series compare value more prominent. https://answers.splunk.com/answers/710781/how-do-you-deal-with-visualization-disparities-in.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

pgadhari
Builder

ohh ya did not see that properly. Thanks for pointing it out. I will try with that.

Also, one more thing, it might be minor - Actually the Y-Series time in the above timechart screenshot, I want to remove day of the week i.e. wed, fri, sat etc. I dont want to display the day of the week. I tried with eval _time = strftime(_time,"%F %T"), but still it is showing the day in the timechart ? what time option will remove it ?

0 Karma

niketnilay
Legend

try

<yourCurrentSearch>
| eval Time=strftime(_time,"%F %T")
| fields - _time
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

pgadhari
Builder

@niketnilay - did you get time to look at the timechart issue I posted ?

0 Karma

pgadhari
Builder

After trying this, the X-Axis labels disappeared and it is no more showing the date timestamp after eval to Time, attached is the image.

https://imgur.com/a/oFnsR51

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!