Splunk Search

X-axis time range

rameshlpatel
Communicator

Hi,

I have timechart graph and i am showing that for the day. like Today, Yesterday etc.

Here problem is when I am seeing chart for today at time of 6 AM then its showing only 6 hrs X -axis line and its growing when time passed.

Here I need whole 24 hrs in X-axis without considering at what time I am seeing for the day.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Let your search run from @d to @d+d instead of using Today which only runs until now. That way your search will cover 24 hours and the timechart will display the entire day.

0 Karma

rameshlpatel
Communicator

I ran same example you given and its showing upto now. Is there any configuration behind this ? I am using SPLUNK 6.1 version.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Works for me:

alt text

Local time is a bit past 6pm, the chart shows empty all the way until midnight.

0 Karma

rameshlpatel
Communicator

Still in X axis _time showing upto current time.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yeah... if you get that message then you may have mixed up the two. Earliest should be @d (00:00 today), and latest should be @d+d (00:00 tomorrow / "24:00" today).

0 Karma

rameshlpatel
Communicator

Should I have to add @d+d instead of 'now' ? If Yes then I am getting message as 'Earliest Time can be greater then Latest'.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?  We’re excited to announce the latest enhancements to Splunk Observability Cloud and share what’s ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...