I was told that the sparkline would show a dip at the end because the time bucket would be partial. So from my understanding if the sparkline would aggregate by every hour and the time would be 13:05 right now, it would show a dip at the end of the sparkline because it would only count five minutes worth of events. The problem is that there should be a lot of continuous events and if the end of the sparkline shows a rapid decline people not familiar with how splunk works would think there is some kind of problem because there is such a huge decrease. Hope this cleared the confusion, thank you for your help.
... View more