Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Chart yes, timechart no? confused

$
0
0
Hello, I am using the following search: index="ips_snaplogic""postsales" lvl="ERROR"| spath| rex mode=sed "s/.*{/{/" | spath output=msg path=Detail.error.message.message | timechart count BY msg When I use timechart, I get a visual. When I use chart, no results. Any idea why? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles