Reporting

Forcing report to chart last month of data?

cpmesh
Engager

I'm trying to create a report that will show a month worth of data in 20 minute spans. I have the spans set at 20 minutes and the time range set to last 30 days but the report only shows the first 8 days of that 30 day period. (the data covers the full 30 day period)

Any suggestions?

Tags (2)
0 Karma
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

Splunk's chart rendering subsystem is configured to only show 500 data rows by default, as each point takes a couple of pixels and it's unlikely that your display device has more than a few thousand pixels. I'm assuming that your table below the chart shows all 2160 rows of data.

Are you just interested in a chart here? If so, why do you need span=20m? If not, is the table correct?

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

Splunk's chart rendering subsystem is configured to only show 500 data rows by default, as each point takes a couple of pixels and it's unlikely that your display device has more than a few thousand pixels. I'm assuming that your table below the chart shows all 2160 rows of data.

Are you just interested in a chart here? If so, why do you need span=20m? If not, is the table correct?

Stephen_Sorkin
Splunk Employee
Splunk Employee

Assuming you have a custom dashboard, you can tweak the maxResultCount property for FlashChart as in http://www.splunk.com/base/Documentation/4.1.4/Developer/ModuleReference#FlashChart. There's no way to change this setting for the charting sections in the UI.

0 Karma

cpmesh
Engager

The table below is correct, I'm just trying to get the chart to display the full month if possible. I have span set to 20m because the data set that I need to average updates every 20 minutes and I need the table to be accurate. The chart displays the full month on the dashboard, I'm hoping to duplicate that chart on the report

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...