I was running a search to display the last one week count for each notable and i used a query like this below
index=notable | search_name = *abc-xyz* | eval date=strftime(_time, "%y-%m-%d) | stats count by date, search_name | chart sum(count) over date by search_name
For this i was receiving only 10 search_name values but it should be 15 in total for the rest it is showing as other, how should we remove the value called other and display the actual values
By default, the chart command shows only the top 10 values. To see more than that, use the limit option. limit=0 shows all values
index=notable
| search_name = *abc-xyz*
| eval date=strftime(_time, "%y-%m-%d)
| stats count by date, search_name
| chart limit=0 sum(count) over date by search_name