Splunk Search

Why is timechart showing OTHER for some values?

nwoolley
Engager
process_inst_id=258600,process_def_id=30,process_name=MIWrite,start_dt=08-OCT-2019-07:39:49,end_dt=,completed=N,running=Running,exe_period=1,avg_exe_period=1,status=GREEN
host = rbm01.plus.netsourcetype = Crontab_SPL
08/10/2019
07:36:18.000    
process_inst_id=258599,process_def_id=5010,process_name=PAYRESP_NORMAL,start_dt=08-OCT-2019-07:36:18,end_dt=08-OCT-2019-07:37:40,completed=Y,running=08-OCT-2019-07:37:40,exe_period=1,avg_exe_period=1,status=GREEN
host = rbm01.plus.netsourcetype = Crontab_SPL

Fields above coming up as "OTHER" when I use timechart oddly, anyone know why?

index=asg "completed=" | timechart count by process_name
0 Karma
1 Solution

solarboyz1
Builder

Usually occurs when hit the default limit of distinct values. add limt=0 to your timechart:

index=asg "completed=" | timechart limit=0 count by process_name

https://docs.splunk.com/Documentation/SplunkCloud/7.2.7/SearchReference/Timechart

If set to limit=0, all distinct values are used. Setting limit=N keeps the N highest scoring distinct values of the split-by field.

View solution in original post

0 Karma

sandeepmakkena
Contributor
... | timechart useother=f count by process_name

You can do this.

0 Karma

solarboyz1
Builder

Usually occurs when hit the default limit of distinct values. add limt=0 to your timechart:

index=asg "completed=" | timechart limit=0 count by process_name

https://docs.splunk.com/Documentation/SplunkCloud/7.2.7/SearchReference/Timechart

If set to limit=0, all distinct values are used. Setting limit=N keeps the N highest scoring distinct values of the split-by field.

0 Karma

nwoolley
Engager

perfect thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...