Splunk Search

Help with timechart

ChhayaV
Communicator

Hi,
This is my query

index=tm_idx host="audit" ID=144 | timechart count by client

its giving me chart shown below but i dont want connected lines rather i shoud be able to see just a dot/square for each login.
And also i want to see client(Admin, Moore etc) name in tool-tip instead of count
how can i do it?

Thanks and regards

alt text

0 Karma

derekarnold
Communicator

Edit your timechart visualization. Under General Options there is a dropdown box called Missing Values. Choose something other than Omit. Try Connect or Treat as Zero instead.

0 Karma

ChhayaV
Communicator

for now i am running on search bar but will be placing in dashboard panel later

0 Karma

somesoni2
Revered Legend

You are running this query in Search bar or in a dashboard panel?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...