All Apps and Add-ons

Quit "OTHER" column from "Call Concurrency and Gateway Utilization" report

radw62
Path Finder

Hello R&A App/Splunk Team

Im working on get monthly "Call Concurrency and Gateway Utilization" reports, and R&A returns 67 GWs, however when I export the report on CSV format, it doesn't appear all 67 GWs , instead only half of them, and one column named "OTHER".

Is there a way to get all the GWs in the same export?? As workaround I had to split the query on two for get all the 67 GWs I need.

Again, thanks for provide us this great tool.

Regards.

0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

We do have a limit=30 in the timechart clause. I'll raise that default to 60 in the next maintenance release. As far as the displayed report having no "other" when the exported results do have an "Other", I'm afraid I can't reproduce that - is it possible that it's just very hard to find the "OTHER" in the dense chart? The chart's legend has little page controls and most often "OTHER" would get pushed to page 2 or page 3.

Anyway, there's a way to fix it, that involves editing something not commonly edited. If you're OK with this here's how. Navigate in the app to "Settings > Advanced Search > Macros". Find the "timechart_for_concurrency(2)" macro and click it. It's quite a large SPL expression but you'll notice within it, a limit=30. Raise that to limit=60 or limit=100 and you won't get an OTHER anymore.

Note - you may also stumble onto, or get told about useother=f. Do not use that. It simply turns off the display of the OTHER column. However it will not make the hidden "other" values display so it's not very useful.

View solution in original post

0 Karma

sideview
SplunkTrust
SplunkTrust

We do have a limit=30 in the timechart clause. I'll raise that default to 60 in the next maintenance release. As far as the displayed report having no "other" when the exported results do have an "Other", I'm afraid I can't reproduce that - is it possible that it's just very hard to find the "OTHER" in the dense chart? The chart's legend has little page controls and most often "OTHER" would get pushed to page 2 or page 3.

Anyway, there's a way to fix it, that involves editing something not commonly edited. If you're OK with this here's how. Navigate in the app to "Settings > Advanced Search > Macros". Find the "timechart_for_concurrency(2)" macro and click it. It's quite a large SPL expression but you'll notice within it, a limit=30. Raise that to limit=60 or limit=100 and you won't get an OTHER anymore.

Note - you may also stumble onto, or get told about useother=f. Do not use that. It simply turns off the display of the OTHER column. However it will not make the hidden "other" values display so it's not very useful.

0 Karma

radw62
Path Finder

Hello, your "limit=100" fix worked!!! Thanks so much.

The same procedure applies to "Busy Hour Calculator" report ?? , Im generating this report and I dont remember if it returned all the GWs...

Regards.

0 Karma

rjthibod
Champion

I do not manage or know about the specifics of the Cisco CDR app/report you reference, but I would venture a guess the issue has to do with their use of the argument limit=30 in an SPL command inside the query that produces the report. It could be inside of chart or transpose or something else. Regardless, you should be able to clone the query/report, and then change that argument to limit=0 in order to get what you are looking for.

0 Karma

radw62
Path Finder

Hello, thanks for the advice

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...