<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About display priority in annotation in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338731#M164362</link>
    <description>&lt;P&gt;Even if you have multiple events coming for a particular time. Splunk breaks them by the indexed time(this means by the order splunk indexed the incoming events). &lt;/P&gt;

&lt;P&gt;For this you need to write your props.conf like below. &lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
DATETIME_CONFIG = CURRENT  ----------("CURRENT" will set the time of the event to the time that the event was&lt;BR /&gt;
    merged from lines, or worded differently, the time it passed through the&lt;BR /&gt;
    aggregator processor.)&lt;/P&gt;

&lt;P&gt;Refer this below link&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Propsconf#Timestamp_extraction_configuration"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Propsconf#Timestamp_extraction_configuration&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So assume you have 200 events per second(Say on 12/13/17 3:38:47). it will break down to milliseconds (12/13/17 3:38:47 101/201/301) &lt;/P&gt;

&lt;P&gt;Now when you display them in timechart it will show in chronological order. &lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 10:14:54 GMT</pubDate>
    <dc:creator>sandyIscream</dc:creator>
    <dc:date>2017-12-13T10:14:54Z</dc:date>
    <item>
      <title>About display priority in annotation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338730#M164361</link>
      <description>&lt;P&gt;How to annotate When multiple events are occurring at the same time, how is it displayed in the time chart?&lt;BR /&gt;
I want to know the priority on display.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 09:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338730#M164361</guid>
      <dc:creator>hasehiro</dc:creator>
      <dc:date>2017-12-13T09:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: About display priority in annotation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338731#M164362</link>
      <description>&lt;P&gt;Even if you have multiple events coming for a particular time. Splunk breaks them by the indexed time(this means by the order splunk indexed the incoming events). &lt;/P&gt;

&lt;P&gt;For this you need to write your props.conf like below. &lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
DATETIME_CONFIG = CURRENT  ----------("CURRENT" will set the time of the event to the time that the event was&lt;BR /&gt;
    merged from lines, or worded differently, the time it passed through the&lt;BR /&gt;
    aggregator processor.)&lt;/P&gt;

&lt;P&gt;Refer this below link&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Propsconf#Timestamp_extraction_configuration"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Admin/Propsconf#Timestamp_extraction_configuration&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So assume you have 200 events per second(Say on 12/13/17 3:38:47). it will break down to milliseconds (12/13/17 3:38:47 101/201/301) &lt;/P&gt;

&lt;P&gt;Now when you display them in timechart it will show in chronological order. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 10:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338731#M164362</guid>
      <dc:creator>sandyIscream</dc:creator>
      <dc:date>2017-12-13T10:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: About display priority in annotation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338732#M164363</link>
      <description>&lt;P&gt;Thank you for anwering.&lt;/P&gt;

&lt;P&gt;However, the indexed time must be obtained form log file.&lt;/P&gt;

&lt;P&gt;I Want to know what condition the event displayed at the top is decided when the time is exactly the same.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 12:51:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-display-priority-in-annotation/m-p/338732#M164363</guid>
      <dc:creator>hasehiro</dc:creator>
      <dc:date>2017-12-13T12:51:44Z</dc:date>
    </item>
  </channel>
</rss>

