Splunk Search

Why is the limit I set for jschart resultTruncationLimit not being applied?

vrmerlin
New Member

I have a jschart in advanced XML that is plotting data from a dbquery; I expect it to get several thousand datapoints. Unfortunately, it's only plotting the first 1,000. I understand that this is a limit in jschart, but the documentation say it can be overridden. I've added this to my HiddenChartFormatter:

<param name="charting.chart.resultTruncationLimit">5000<param>

However, the chart behaves exactly the same -- still gives a truncation error that the chart too many datapoints. Any ideas what I might be doing wrong?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I see. To avoid that, switch from specifying span=5m to specifying bins=1000 minspan=5m. That will cause the 7-day search to use about 337 30-minute spans.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I see. To avoid that, switch from specifying span=5m to specifying bins=1000 minspan=5m. That will cause the 7-day search to use about 337 30-minute spans.

vrmerlin
New Member

that worked -- thank you!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

IIRC the default value can be overridden, but not beyond a certain limit. That limit may very well be around 1000.

What are you trying to plot, and how are you displaying it to actually see 5000 distinct values?

0 Karma

vrmerlin
New Member

I'm plotting several series of CPU percentages on a timechart, in 5min intervals. A selector at the top allows the user to select between 1 day, 3 days, or 7 days. The 7 days select is only partially displaying because there are too many datapoints. I resolve it, i created an additional selection box to change the interval, but it's causing some end user confusion.

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...