Splunk Search

Timechart limit 1000 results per series, can I increase this?

paddygriffin
Path Finder

Example: I want a second-by-second stat for the past 24 hours. The following message shows: "These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached".
How would I alter that limit?

Tags (2)

sloshburch
Splunk Employee
Splunk Employee

If you turn this into a dashboard, you can use the charting.data.count option to set a higher limit than the default of 1000 (even unlimited (0) if you're feeling dangerous).
See Chart configuration reference's General chart properties

0 Karma

vinceaws
New Member

This doesn't work in 7.4.X

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Hmmm. Latest release is 7.2.4, not 7.4. Is that what you mean? If so, I see it's still valid as per the documentation. You may want to verify if you found a bug (try another environment or make sure it's not the specific dashboard) and if so, open a support request for validation of the bug.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...