I'm trying to create a report that will show a month worth of data in 20 minute spans. I have the spans set at 20 minutes and the time range set to last 30 days but the report only shows the first 8 days of that 30 day period. (the data covers the full 30 day period)
Any suggestions?
Splunk's chart rendering subsystem is configured to only show 500 data rows by default, as each point takes a couple of pixels and it's unlikely that your display device has more than a few thousand pixels. I'm assuming that your table below the chart shows all 2160 rows of data.
Are you just interested in a chart here? If so, why do you need span=20m? If not, is the table correct?
Splunk's chart rendering subsystem is configured to only show 500 data rows by default, as each point takes a couple of pixels and it's unlikely that your display device has more than a few thousand pixels. I'm assuming that your table below the chart shows all 2160 rows of data.
Are you just interested in a chart here? If so, why do you need span=20m? If not, is the table correct?
Assuming you have a custom dashboard, you can tweak the maxResultCount property for FlashChart as in http://www.splunk.com/base/Documentation/4.1.4/Developer/ModuleReference#FlashChart. There's no way to change this setting for the charting sections in the UI.
The table below is correct, I'm just trying to get the chart to display the full month if possible. I have span set to 20m because the data set that I need to average updates every 20 minutes and I need the table to be accurate. The chart displays the full month on the dashboard, I'm hoping to duplicate that chart on the report