I have a table which drills down to change a chart:
<row>
<panel>
<table>
<title>Exchanges</title>
<search>
<query>`MS_DDI_Microservices` metric_name="Rate:Exchange:*"
| rex field=metric_name ".*:(?<Exchange>[^:]*):(?<direction>[^:]*)$$"
| chart avg(Average) by Exchange, direction</query>
<earliest>$time.earliest$</earliest>
<latest>$time.latest$</latest>
<sampleRatio>1</sampleRatio>
<refresh>$refresh$</refresh>
</search>
<drilldown>
<set token="exchange">$row.Exchange$</set>
</drilldown>
<option name="count">20</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">cell</option>
<option name="percentagesRow">false</option>
<option name="rowNumbers">false</option>
<option name="totalsRow">false</option>
<option name="wrap">true</option>
</table>
</panel>
<panel>
<chart>
<title>$exchange$ Rate</title>
<search>
<query>`MS_DDI_Microservices` metric_name="Rate:Exchange:$exchange$:*"
| rex field=metric_name ":(?<direction>[^:]*)$$"
| timechart avg(Average) by direction</query>
<earliest>$time.earliest$</earliest>
<latest>$time.latest$</latest>
<sampleRatio>1</sampleRatio>
<refresh>$refresh$</refresh>
</search>
<option name="charting.axisTitleX.visibility">collapsed</option>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.axisTitleY2.visibility">collapsed</option>
<option name="charting.axisY.includeZero">1</option>
<option name="charting.chart">line</option>
<option name="charting.chart.nullValueMode">connect</option>
<option name="charting.legend.placement">right</option>
</chart>
</panel>
</row>
When the dashboard draws initially the chart has a y-axis that just includes the data (currently 7.5). When I select a row in the table the chart redraws with the y-axis up to 100, well over what is required. Selecting back to the original row keeps the y-axis maximum value of 100, which renders the data as a tiny curve at the very bottom of the chart.
Any thoughts? I've left the y-axis max at the default, documented as auto. I think it works right the first time but not afterwards.
Splunk Enterprise 6.6.2
... View more