Splunk Search

Why is base search only showing several hours of events instead of 24 hours?

Snigdha95
New Member

I have a dashboard where I have used base search in each panel. Within the dashboard, I have 40 different panels and in all the panel I have used timechart count by the severity field.

  <panel>
  <event>
    <title>BASE SEARCH PANEL</title>
    <search id="id">
      <query>index="abc" sourcetype=xyz </query>
      <earliest>$Time_token.earliest$</earliest>
      <latest>$Time_token.latest$</latest>
    </search>
    <option name="count">1</option>
    <option name="list.drilldown">none</option>
  </event>
</panel>

<row>
<panel>
  <title>ABC</title>
  <chart>
    <search base="id">
      <query>search "my search query| timechart values(field)"</query>
    </search>
    <option name="charting.axisLabelsX.majorLabelStyle.rotation">-90</option>
    <option name="charting.axisLabelsY.majorUnit">1</option>
    <option name="charting.axisTitleX.visibility">collapsed</option>
    <option name="charting.axisTitleY.text">Good (1)</option>
    <option name="charting.axisY.maximumNumber">1</option>
    <option name="charting.axisY.minimumNumber">0</option>
    <option name="charting.chart">line</option>
    <option name="charting.chart.nullValueMode">gaps</option>
    <option name="charting.drilldown">all</option>
    <option name="charting.layout.splitSeries">1</option>
    <option name="charting.legend.placement">top</option>
    <option name="charting.lineWidth">2</option>
    <option name="charting.seriesColors">[430DEB,ED7212]</option>
    <option name="height">317</option>
    <option name="refresh.display">progressbar</option>
    <option name="trellis.enabled">0</option>
    <option name="trellis.scales.shared">1</option>
    <option name="trellis.size">medium</option>
  </chart>
</panel>
<panel>
  <title>XYZ</title>
  <chart>
    <search base="id">
      <query>search "my search query| timechart values(field)"</query>
    </search>
    <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
    <option name="charting.axisLabelsX.majorLabelStyle.rotation">-90</option>
    <option name="charting.axisLabelsY.majorUnit">1</option>
    <option name="charting.axisTitleX.visibility">collapsed</option>
    <option name="charting.axisTitleY.text">Good (1)</option>
    <option name="charting.axisTitleY.visibility">visible</option>
    <option name="charting.axisTitleY2.visibility">visible</option>
    <option name="charting.axisX.abbreviation">none</option>
    <option name="charting.axisX.scale">linear</option>
    <option name="charting.axisY.abbreviation">none</option>
    <option name="charting.axisY.maximumNumber">1</option>
    <option name="charting.axisY.minimumNumber">0</option>
    <option name="charting.axisY.scale">linear</option>
    <option name="charting.axisY2.abbreviation">none</option>
    <option name="charting.axisY2.enabled">0</option>
    <option name="charting.axisY2.scale">inherit</option>
    <option name="charting.chart">line</option>
    <option name="charting.chart.bubbleMaximumSize">50</option>
    <option name="charting.chart.bubbleMinimumSize">10</option>
    <option name="charting.chart.bubbleSizeBy">area</option>
    <option name="charting.chart.nullValueMode">gaps</option>
    <option name="charting.chart.showDataLabels">none</option>
    <option name="charting.chart.sliceCollapsingThreshold">0.01</option>
    <option name="charting.chart.stackMode">default</option>
    <option name="charting.chart.style">shiny</option>
    <option name="charting.drilldown">all</option>
    <option name="charting.layout.splitSeries">1</option>
    <option name="charting.layout.splitSeries.allowIndependentYRanges">0</option>
    <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
    <option name="charting.legend.mode">standard</option>
    <option name="charting.legend.placement">top</option>
    <option name="charting.lineWidth">2</option>
    <option name="charting.seriesColors">[430DEB,ED7212]</option>
    <option name="height">274</option>
    <option name="refresh.display">progressbar</option>
    <option name="trellis.enabled">0</option>
    <option name="trellis.scales.shared">1</option>
    <option name="trellis.size">medium</option>
  </chart>
</panel>

My problem is that currently, whenever I ran this dashboard, the timechart only displays results for the last 3-4 hours (Not the entire 24 hour frame) whereas I have results for 24hours. When I search from the panel, I could see the statistics result showing 24 hour details, which means my search query is fine.

Based on the code shown above and my base search, what am I doing wrong? Is there something wrong with my code/logic?

I appreciate any comments/guidance/hints.

Thanks.

0 Karma

seemanshu
Path Finder

Hi Snigdha95,
The count option is in some how affecting the results. You should first check all the results without applying the limit on the count of results.
Hopefully, that would help!

0 Karma

BainM
Communicator

Hi Snigdha95-
I am pretty sure your
option name="count"-1-option

is affecting it in some manner.

Check out this Answers Link:
https://answers.splunk.com/answers/188992/how-to-dynamically-change-number-of-rows-displayed.html

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...