Splunk Search

splunk chart issue


Hi ,

In splunk, I am trying to create chart for each day (24 hrs) with span of every minute.

e.g. index="monitor" source=* | timecart span=1m avg(time)

but to do this its giving following msg :

These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached.

Tags (3)
0 Karma

Splunk Employee
Splunk Employee

If you turn this into a dashboard, you can use the charting.data.count option to set a higher limit (even unlimited (0) if you're feeling dangerous).

0 Karma

Revered Legend
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!