All Apps and Add-ons

Why my timechart command is truncating the results in linegraph?

mprreddy51
Explorer

Hi Splunkers,

I have a panel with timechart command and visualization is line graph .If I select the timerange picker for one day it is showing fine.when i select for 7days or 30days(or larger timespan), it is truncating the results and showing for 1 or 2 days data only in line graph.How to overcome this isssue.I changed limit in web.conf also but no luck.

Thanks,
P

0 Karma

lguinn2
Legend

The line chart visualization has a limit to the number of points that it can show. If you have explicitly set a span in your timechart command (eg. span=1m), it may work fine for a shorter timerange, but create problems for longer time ranges. And while you may be able to edit limits, I don't have any experience with that. And ultimately, if you let users pick a timerange, someone may pick something that blows out the limits anyway.

One solution is to remove the span option from the timechart command; then Splunk will automatically choose a span based on the overall timerange. For example, Splunk chooses a 30 minute span for a 24 hour timerange, and a 1 day span for a 30 day timerange.

Or, you can use @martin_mueller's excellent answer here: Why is the limit I set for jschart resultTruncationLimit not being applied?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...