Splunk Search

Why doesn't my columnchart show all events?

Oerstier
New Member

For monitoring purposes I have a columnchart showing the number of events per minute for the last 30 minutes ("30 minute window"). I've noticed several times that the columnchart doesn't show the correct number of events, even when missing events show up in the search query used to create the columnchart. This is the query I use;

index="prod" application="wsp2" source="/var/log/httpd/access_log" | timechart count

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...