Splunk Search

Timechart limit 1000 results per series, can I increase this?

Path Finder

Example: I want a second-by-second stat for the past 24 hours. The following message shows: "These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached".
How would I alter that limit?

Tags (2)

Ultra Champion

If you turn this into a dashboard, you can use the charting.data.count option to set a higher limit than the default of 1000 (even unlimited (0) if you're feeling dangerous).
See Chart configuration reference's General chart properties

0 Karma

New Member

This doesn't work in 7.4.X

0 Karma

Ultra Champion

Hmmm. Latest release is 7.2.4, not 7.4. Is that what you mean? If so, I see it's still valid as per the documentation. You may want to verify if you found a bug (try another environment or make sure it's not the specific dashboard) and if so, open a support request for validation of the bug.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!