Splunk Search

X-axis time range

rameshlpatel
Communicator

Hi,

I have timechart graph and i am showing that for the day. like Today, Yesterday etc.

Here problem is when I am seeing chart for today at time of 6 AM then its showing only 6 hrs X -axis line and its growing when time passed.

Here I need whole 24 hrs in X-axis without considering at what time I am seeing for the day.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Let your search run from @d to @d+d instead of using Today which only runs until now. That way your search will cover 24 hours and the timechart will display the entire day.

0 Karma

rameshlpatel
Communicator

I ran same example you given and its showing upto now. Is there any configuration behind this ? I am using SPLUNK 6.1 version.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Works for me:

alt text

Local time is a bit past 6pm, the chart shows empty all the way until midnight.

0 Karma

rameshlpatel
Communicator

Still in X axis _time showing upto current time.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yeah... if you get that message then you may have mixed up the two. Earliest should be @d (00:00 today), and latest should be @d+d (00:00 tomorrow / "24:00" today).

0 Karma

rameshlpatel
Communicator

Should I have to add @d+d instead of 'now' ? If Yes then I am getting message as 'Earliest Time can be greater then Latest'.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...