Splunk Search

Why is base search only showing several hours of events instead of 24 hours?

Snigdha95
New Member

I have a dashboard where I have used base search in each panel. Within the dashboard, I have 40 different panels and in all the panel I have used timechart count by the severity field.

  <panel>
  <event>
    <title>BASE SEARCH PANEL</title>
    <search id="id">
      <query>index="abc" sourcetype=xyz </query>
      <earliest>$Time_token.earliest$</earliest>
      <latest>$Time_token.latest$</latest>
    </search>
    <option name="count">1</option>
    <option name="list.drilldown">none</option>
  </event>
</panel>

<row>
<panel>
  <title>ABC</title>
  <chart>
    <search base="id">
      <query>search "my search query| timechart values(field)"</query>
    </search>
    <option name="charting.axisLabelsX.majorLabelStyle.rotation">-90</option>
    <option name="charting.axisLabelsY.majorUnit">1</option>
    <option name="charting.axisTitleX.visibility">collapsed</option>
    <option name="charting.axisTitleY.text">Good (1)</option>
    <option name="charting.axisY.maximumNumber">1</option>
    <option name="charting.axisY.minimumNumber">0</option>
    <option name="charting.chart">line</option>
    <option name="charting.chart.nullValueMode">gaps</option>
    <option name="charting.drilldown">all</option>
    <option name="charting.layout.splitSeries">1</option>
    <option name="charting.legend.placement">top</option>
    <option name="charting.lineWidth">2</option>
    <option name="charting.seriesColors">[430DEB,ED7212]</option>
    <option name="height">317</option>
    <option name="refresh.display">progressbar</option>
    <option name="trellis.enabled">0</option>
    <option name="trellis.scales.shared">1</option>
    <option name="trellis.size">medium</option>
  </chart>
</panel>
<panel>
  <title>XYZ</title>
  <chart>
    <search base="id">
      <query>search "my search query| timechart values(field)"</query>
    </search>
    <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
    <option name="charting.axisLabelsX.majorLabelStyle.rotation">-90</option>
    <option name="charting.axisLabelsY.majorUnit">1</option>
    <option name="charting.axisTitleX.visibility">collapsed</option>
    <option name="charting.axisTitleY.text">Good (1)</option>
    <option name="charting.axisTitleY.visibility">visible</option>
    <option name="charting.axisTitleY2.visibility">visible</option>
    <option name="charting.axisX.abbreviation">none</option>
    <option name="charting.axisX.scale">linear</option>
    <option name="charting.axisY.abbreviation">none</option>
    <option name="charting.axisY.maximumNumber">1</option>
    <option name="charting.axisY.minimumNumber">0</option>
    <option name="charting.axisY.scale">linear</option>
    <option name="charting.axisY2.abbreviation">none</option>
    <option name="charting.axisY2.enabled">0</option>
    <option name="charting.axisY2.scale">inherit</option>
    <option name="charting.chart">line</option>
    <option name="charting.chart.bubbleMaximumSize">50</option>
    <option name="charting.chart.bubbleMinimumSize">10</option>
    <option name="charting.chart.bubbleSizeBy">area</option>
    <option name="charting.chart.nullValueMode">gaps</option>
    <option name="charting.chart.showDataLabels">none</option>
    <option name="charting.chart.sliceCollapsingThreshold">0.01</option>
    <option name="charting.chart.stackMode">default</option>
    <option name="charting.chart.style">shiny</option>
    <option name="charting.drilldown">all</option>
    <option name="charting.layout.splitSeries">1</option>
    <option name="charting.layout.splitSeries.allowIndependentYRanges">0</option>
    <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
    <option name="charting.legend.mode">standard</option>
    <option name="charting.legend.placement">top</option>
    <option name="charting.lineWidth">2</option>
    <option name="charting.seriesColors">[430DEB,ED7212]</option>
    <option name="height">274</option>
    <option name="refresh.display">progressbar</option>
    <option name="trellis.enabled">0</option>
    <option name="trellis.scales.shared">1</option>
    <option name="trellis.size">medium</option>
  </chart>
</panel>

My problem is that currently, whenever I ran this dashboard, the timechart only displays results for the last 3-4 hours (Not the entire 24 hour frame) whereas I have results for 24hours. When I search from the panel, I could see the statistics result showing 24 hour details, which means my search query is fine.

Based on the code shown above and my base search, what am I doing wrong? Is there something wrong with my code/logic?

I appreciate any comments/guidance/hints.

Thanks.

0 Karma

seemanshu
Path Finder

Hi Snigdha95,
The count option is in some how affecting the results. You should first check all the results without applying the limit on the count of results.
Hopefully, that would help!

0 Karma

BainM
Communicator

Hi Snigdha95-
I am pretty sure your
option name="count"-1-option

is affecting it in some manner.

Check out this Answers Link:
https://answers.splunk.com/answers/188992/how-to-dynamically-change-number-of-rows-displayed.html

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...