Splunk Search

Why two charts show different results?

thiru25
Explorer

Hello, I have two different chart results (visualization) for queries that start at 9:15AM and finsih 4:15PM. When I open a dashboard at 11AM, the data is available only up to 11AM but the one chart visualization start at 9:15AM and finishes at 4:15PM regardless of data availability.

Is there a way to change this?

Tags (1)
0 Karma

thiru25
Explorer

yes, I need to hardcode the timeline because I need to stop the quert at 4:15PM, is there a way around it?

0 Karma

yannK
Splunk Employee
Splunk Employee

Verify is you didn't hard coded the timerange in the search.
On a dashboard, you can use the edit the XML and check the earliest and latest parameters.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...