In splunk, I am trying to create chart for each day (24 hrs) with span of every minute.
e.g. index="monitor" source=* | timecart span=1m avg(time)
but to do this its giving following msg :
These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached.
If you turn this into a dashboard, you can use the charting.data.count option to set a higher limit (even unlimited (0) if you're feeling dangerous).