Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Querying raw data point for 24hr window time chart not displaying all values?

$
0
0

source=<source.log> "KeyOfThis" | table theRawValue, _time | chart values(theRawValue) by _time

So, when I run this query there is an event with a large Raw value for a given date that I need to display (and for any large value that looks out of control). I can get this data value to show up in my line graph within 15min timeframe. However, when I try to fit it within the last 8hrs (let alone the last 24hrs) for that same chart the value doesn't show up because there is too much data to display apparently as the day/month for that data point is not showing up. The date range is short by two days so that value is not showing up in the chart.

How can I display all the raw values within an 8hr or 24hr time frame without having to average?


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>