Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Chart/Report Only Showing 500 Events

$
0
0

Hi, here is my search:

| dbquery "MYDB" "SELECT lastuseraction FROM user" | eval lastuseraction=strftime(lastuseraction,"%Y-%m-%d") | stats count by lastuseraction | rename lastuseraction as "Date", count as "# of Actions" | sort by -Date

The results seem to be all there in regular table mode, but when I switch to Results Chart or try to create a Report it looks like it's limited to 500 events

Thinking I need to add something limit=0 or something, but not sure how to work it into this particular search

Thanks :)


Viewing all articles
Browse latest Browse all 13053


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>