It seems that since upgrading splunk to v5, any searches which are grouped by a count. e.g.:
“test” | stats count by host
Do NOT show the flashtimeline at the top of the search results.
The flashtimeline DID show on the same queries before our upgrade.
If I remove the count by. E.g. above just search for. e.g.:
...the flashtimeline does display.
Any advice would be appreciated.
I've been talking to splunk about this, and they have provided an answer that I will share here.
There is a dropdown up the top which has the three options. "Smart", "Fast" or "Verbose". Selecting "Verbose" ensures that the flashtimeline is displayed.