Just as an FYI, I find that a chart is typically most readable when the max value is around 3/4 of the Y-scale so you might want to do something like this:
<eval token="chartmax">ceiling($result.max_duration$*4/300)*100</eval>
... View more
I know this is an old post but every Splunk enterprise server in a distributed deployment, except indexers, should have outputs.conf to forward its internal logs to the indexer(s). Also, the MC doesn't have a HF role designated, so I assume you aren't referring to MC roles here, just a function that server is performing. Is that right?
... View more