I have 26 days of events (Monday 9/15 through Friday 10/10) piped to a timechart span=7d.
I'd like to have 3 buckets of 7 days each, and one bucket with the 5 remainder days. It doesn't matter to me if the remainder bucket is at the beginning or end but it would be nice if Splunk was consistent about it.
Instead, my buckets begin at 9/15, 9/22, 9/29 (Mondays), 10/3, 10/10 (Fridays) which means I have 5 buckets, instead of 4,
with 7, 7, 4, 7, and 1 day in them.
How can I make timechart behave reasonably?
I'm running Splunk 6.1.2
... View more