Splunk Search

unable to see all the events in visualisation

roopeshetty
Path Finder

Hi

We are running this search [host=uswebserver12 |timechart span=5m avg(PercentProcessorTime) as CPU_Usage] and getting the required events. But once we go to visualization we are not getting the full chart but only for few days with this error message "These results may be truncated. This visualization is configured to display a maximum of 1000 results per series, and that limit has been reached" . We just went through googling about this and found that we need to change charting.data.count values in simple XML. But we could not find anywhere where is this simple XML file is located so that we can edit it. Is it located inside any folders of splunk server or we need to edit it in the spluk web console itself. Kindly advice us

Tags (1)
0 Karma

roopeshetty
Path Finder

Hi rwang,

in these documents also its written that we need to edit the charting.data.count values in simple xml. But its no where written where these simple xml files exists so that we can edit them. We tried searching whole splunk installation directory but but could not find these simple xml files.

0 Karma

rwang_splunk
Splunk Employee
Splunk Employee

Hi Roopesh

the xml is not in any of the files or directories of splunk installation file. If you want to edit it, you have to save your spl as a dashboard, then go to 'edit source' to add the charting.data.count in the simple xml code. you can set it to 0 if you want to retrieve all data.

Renee

roopeshetty
Path Finder

Hi rwang, ... got it... So we can expand the visualiation in dashboards from 1000 to any number but not in reports right?. correct me if i am wrong.

0 Karma

rwang_splunk
Splunk Employee
Splunk Employee

Correct. Save as a dashboard first, then edit the source.

jkat54
SplunkTrust
SplunkTrust

You have to save the timechart onto a dashboard, then edit the dashboard source to get to the simple xml values.

0 Karma

roopeshetty
Path Finder

Hi Jkat54,

Thanks for you response. But we wanted to expand the chart capacity for search Visualisation itself not for dash boards. Please advice

regards
Roopesh

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...