Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Chart Drill Down changes Date time range

$
0
0
I have dashboard with chart inside it. The query of the chart is: **base_search | eval _time = time| bucket _time span=24h | chart count over _time by app_risk| fields _time,Critical,High,Medium,Low** The drill down settings are: On Click=Link to Search & Auto. When clicking on "High" category on specific date, I would like to see the events related to this combination of risk and date. For some reason, I have no results after drilling down. **For example: I click on events from Sep 15 - I expect the rime range to be Sep 15 00:00:00,000 to Sep 15 23:59:59,999 but (!) the time range is Sep 15 00:00:00,000 to Sep 15 00:00:00,001** Can someone tell me why the results are not related to the specific column date?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>