Hi Splunkers,
I have a panel with timechart command and visualization is line graph .If I select the timerange picker for one day it is showing fine.when i select for 7days or 30days(or larger timespan), it is truncating the results and showing for 1 or 2 days data only in line graph.How to overcome this isssue.I changed limit in web.conf also but no luck.
Thanks,
P
The line chart visualization has a limit to the number of points that it can show. If you have explicitly set a span in your timechart command (eg. span=1m), it may work fine for a shorter timerange, but create problems for longer time ranges. And while you may be able to edit limits, I don't have any experience with that. And ultimately, if you let users pick a timerange, someone may pick something that blows out the limits anyway.
One solution is to remove the span option from the timechart command; then Splunk will automatically choose a span based on the overall timerange. For example, Splunk chooses a 30 minute span for a 24 hour timerange, and a 1 day span for a 30 day timerange.
Or, you can use @martin_mueller's excellent answer here: Why is the limit I set for jschart resultTruncationLimit not being applied?