All Apps and Add-ons

In Event Timeline viz app: does it possible to have data displayed in specific order without dynamic rearrangement?

edvinas
New Member

Hi,

I like Event Timeline viz app, but I want to have one more feature.
I want to have ability to display data one in a row in specific order without dynamic rearrangement.
Now I just have made separate group for every data item, so I have all my data in separate lines with correct view.

Maybe its possible to have such visualization without using "separate group for every data item"?
Or just to have two-level grouping solution.

Tags (1)
0 Karma

danspav
SplunkTrust
SplunkTrust

Hi @edvinas,

The events in the Event Timeline Viz are listed in time-order.

Take this example - two events have the same date, so they appear in the same order as the results:

Event Timeline Viz

If you have the time axis at the bottom, the events will be flipped, so the order is preserved. The first event in the results is the closest to the axis.

If they have different dates, they will appear on the time line in time order.

If you want a specific order, can you manipulate the _time field?

Perhaps you can give an example of how you want it ordered.

0 Karma

edvinas
New Member

The idea is to have all events listed "down and to the right" according order.
I have made separate group for every data item, so I have all my data in separate lines with correct view:
alt text

If I would not use separate groups, I got all events listed "to the right", but squeezed into least rows as possible, and visualization changes depending on zoom:
alt text

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...