Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

-1 value at _time field using timechart

$
0
0
Hello Splunkers. I'm having an issue with timechart; Scenario: I have a index that contains summarized data. I want to create a timechart showing the sum of bytes used. However, in the field _time, I get some dates OK and then I get a -1 value. After that, _time goes back to start of the epoch time: ![alt text][1] [1]: /storage/temp/170179-comp.png At first I imagined that it was related to summarization issues, but the same occurs on the data indexed directly from the ironports. Have you guys ever seen something like that? Thanks in advance!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>