The above used to work for me. That is, simply use "sort" to order the stats under in the Statistics tab and then the Visualisation tab would graph them in the sort order.
This stopped working, I think, after an upgrade of Splunk (we are now running version 7.2.4). What I get now is Count Vs Time (aka similar to the first screen grab regardless of the sort order).
Has anyone else experienced this? And is there a work around (I simply want a graph similar to the second screen grab above)?
... View more