Splunk Search

Timechart limit 1000 results per series, can I increase this?

paddygriffin
Path Finder

Example: I want a second-by-second stat for the past 24 hours. The following message shows: "These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached".
How would I alter that limit?

Tags (2)

sloshburch
Ultra Champion

If you turn this into a dashboard, you can use the charting.data.count option to set a higher limit than the default of 1000 (even unlimited (0) if you're feeling dangerous).
See Chart configuration reference's General chart properties

0 Karma

vinceaws
New Member

This doesn't work in 7.4.X

0 Karma

sloshburch
Ultra Champion

Hmmm. Latest release is 7.2.4, not 7.4. Is that what you mean? If so, I see it's still valid as per the documentation. You may want to verify if you found a bug (try another environment or make sure it's not the specific dashboard) and if so, open a support request for validation of the bug.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...