Gah, thank you for posting this, I was second guessing myself. I'm running into the same issue, not realizing it was the colons. This is not browser-specific: I can repo in Safari and Firefox as well. If I may tweak your repo into something that Splunk causes: | makeresults | eval value=1 | timechart fixedrange=false max(value) as max, count by value Chart overlay will not work with the timechart result because Splunk creates the fields "count: 1" and "max: 1". Workaround: rename all the fields without the colon: | rename "count: 1" as count_1, "max: 1" as max_1 Now you can put either field into the overlay. This doesn't scale with lots of data though. My Splunk: Splunk Enterprise Version: 8.2.2.1 Build: ae6821b7c64b
... View more