Is it possible to use timechart, or another command, to display the results over a time series but instead of the single data point of when the event occurred, it can expand the width of the event to cover the time span?
I was going to show this in an enhanced timeline but I'm displaying events over 60 days and ones that has a duration of a day or two are hard to see.
I used rex and eval to extract date time fields for the "Start" and "End" of the event
Hi @michaeler,
it isn't so easy, but if you install the timeline app (https://splunkbase.splunk.com/app/3120) and you follow the instructions and samples, you can have what you're serching.
Ciao.
Giuseppe