Splunk Search

X-axis time range

rameshlpatel
Communicator

Hi,

I have timechart graph and i am showing that for the day. like Today, Yesterday etc.

Here problem is when I am seeing chart for today at time of 6 AM then its showing only 6 hrs X -axis line and its growing when time passed.

Here I need whole 24 hrs in X-axis without considering at what time I am seeing for the day.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Let your search run from @d to @d+d instead of using Today which only runs until now. That way your search will cover 24 hours and the timechart will display the entire day.

0 Karma

rameshlpatel
Communicator

I ran same example you given and its showing upto now. Is there any configuration behind this ? I am using SPLUNK 6.1 version.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Works for me:

alt text

Local time is a bit past 6pm, the chart shows empty all the way until midnight.

0 Karma

rameshlpatel
Communicator

Still in X axis _time showing upto current time.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yeah... if you get that message then you may have mixed up the two. Earliest should be @d (00:00 today), and latest should be @d+d (00:00 tomorrow / "24:00" today).

0 Karma

rameshlpatel
Communicator

Should I have to add @d+d instead of 'now' ? If Yes then I am getting message as 'Earliest Time can be greater then Latest'.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...