Splunk Search

Why is the limit I set for jschart resultTruncationLimit not being applied?

vrmerlin
New Member

I have a jschart in advanced XML that is plotting data from a dbquery; I expect it to get several thousand datapoints. Unfortunately, it's only plotting the first 1,000. I understand that this is a limit in jschart, but the documentation say it can be overridden. I've added this to my HiddenChartFormatter:

<param name="charting.chart.resultTruncationLimit">5000<param>

However, the chart behaves exactly the same -- still gives a truncation error that the chart too many datapoints. Any ideas what I might be doing wrong?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I see. To avoid that, switch from specifying span=5m to specifying bins=1000 minspan=5m. That will cause the 7-day search to use about 337 30-minute spans.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I see. To avoid that, switch from specifying span=5m to specifying bins=1000 minspan=5m. That will cause the 7-day search to use about 337 30-minute spans.

vrmerlin
New Member

that worked -- thank you!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

IIRC the default value can be overridden, but not beyond a certain limit. That limit may very well be around 1000.

What are you trying to plot, and how are you displaying it to actually see 5000 distinct values?

0 Karma

vrmerlin
New Member

I'm plotting several series of CPU percentages on a timechart, in 5min intervals. A selector at the top allows the user to select between 1 day, 3 days, or 7 days. The 7 days select is only partially displaying because there are too many datapoints. I resolve it, i created an additional selection box to change the interval, but it's causing some end user confusion.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...