when creating a timechart, it contains a maximum of 10 elements (lines, bars, etc) + one "other". The elements that are aggregated in "other" are those that have the lowest count. In my particular case, I am very interested in those elements. How can I configure the timechart to display all (or at least more of) the elements? Also, when I select the "other" category in the legend, splunk displays an empty timechart because it can't find any log entries whose element value is actually "other". How can I see those elements that have been aggregated?
... View more