Splunk Search

when I use timechart with "sum" why does the graph only show me a graph of events

rogerdpack
Path Finder

When using this query:

index=development host=*app.dev.dps "dgs_size" | timechart sum(dgs_size)

It doesn't graph the sum, only the events, what gives?

Tags (2)
0 Karma
1 Solution

rogerdpack
Path Finder

Turns out that the "top" graph is always of events, and to see the "real" graph, you need to click the right tiny icon to show it. Odd. See http://twitpic.com/atkfn7

View solution in original post

0 Karma

rogerdpack
Path Finder

Turns out that the "top" graph is always of events, and to see the "real" graph, you need to click the right tiny icon to show it. Odd. See http://twitpic.com/atkfn7

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...