Splunk Search

Timechart limit 1000 results per series, can I increase this?

paddygriffin
Path Finder

Example: I want a second-by-second stat for the past 24 hours. The following message shows: "These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached".
How would I alter that limit?

Tags (2)

sloshburch
Splunk Employee
Splunk Employee

If you turn this into a dashboard, you can use the charting.data.count option to set a higher limit than the default of 1000 (even unlimited (0) if you're feeling dangerous).
See Chart configuration reference's General chart properties

0 Karma

vinceaws
New Member

This doesn't work in 7.4.X

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Hmmm. Latest release is 7.2.4, not 7.4. Is that what you mean? If so, I see it's still valid as per the documentation. You may want to verify if you found a bug (try another environment or make sure it's not the specific dashboard) and if so, open a support request for validation of the bug.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...