I am working on statsing firewall data into a sparkline. However, when I run the search, the sparkline caps out at 1800 results. This ends up being an issue because some sparklines end up just looking like a flat line, which is not very useful. Is there a way to work around this/a fix to this?
| tstats count from datamodel=firewall where firewall.signature!="(9999)" by firewall.signature, _time, span=1ms
| stats sparkline sum(count) by log.threat_name
Sparkline limit @ 1800