Hi,
I have a field "host" that contain more than 10 values.
When I issue "... | timechart count by host", timechart shows only 10 hosts and others.
Is it possible to configure the number of field values I can display in a timechart?
How do I configure simple XML views to show more than 10 host in a timechart?
Thanks in advance!
sure, if you read the docs for timechart you'll see there is a setting called limit. If you set this to 0 it will not limit the results (by default its 10).
|timechart count by blah limit=0
http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/timechart
Although there will be a limit to how much data the timechart can show 🙂
sure, if you read the docs for timechart you'll see there is a setting called limit. If you set this to 0 it will not limit the results (by default its 10).
|timechart count by blah limit=0
http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/timechart
Although there will be a limit to how much data the timechart can show 🙂