I have a search that returns me 3 fields (let's say country, _time, count)
I want to show these results in a bubble chart but the X axis (_time) instead of returning dates, it returns 0, 1, 2, 3 etc - it's as if instead of taking the actual date it is taking the line number where the _time field is populated and using that.
I've been playing with date formats and other options but it makes no difference.
Hopefully one of you Splunk gurus can put me out of my misery and let me know what I'm doing wrong!
... View more