Hello,
I have a strange problem in my instance of Splunk Enterprise and have not found solution.
Recently migrated to Splunk Enterprise version 6.2.4 to 6.3.0. After that come problems in realizing consuntas superir to 7 days, for example "earliest=-30d@d".
Using the timechart, statistics run from left to right from the earliest to latest time. However, following right time runs to and from the past coming up to September 1972.
This problem occurs with any index, including indexs Splunk example: _INTERNAL.
When I use ranges of 7 days or less, this problem does not occur, example "earliest=-7d@d"
Anyone have any suggestions on how to solve this problem?
Thank you.
Steps Reproduced:
1- index=_internal earliest=-1d@d | timechart count by host - Ok
2 - index=_internal earliest=-7d@d | timechart count by host - Ok
3 - index=_internal earliest=-8d@d | timechart count by host - Invalid value "-8d@d" for time term 'earliest'
4 - index=_internal earliest=-10d@d | timechart count by host - Problems in graph presentation. Appears at the far right of the graph 23 September 1972.
5 - index=_internal earliest=-30d@d | timechart count by host - Problems in graph presentation. Appears at the far right of the graph 23 September 1972.
6 - 5 - index=_internal earliest=-90d@d | timechart count by host - Problems in graph presentation. Appears at the far right of the graph 23 September 1972.
... View more