Splunk Search

Deselect option in timeline.

rahulrwt23
New Member

What 'Deselect' option in the timeline will do? Will it run the new search or not?

Tags (1)
0 Karma

Javip
Path Finder

I suppose you mean when you do a selection on timeline in search page, only if you click on "Zoom to Selection" this filters temporary your initial query and you can visualize only events inside your new selected period of time. "Deselect" option only deactivates your selection in timeline and it doesn't run you query.

Only in case you zoom in or zoom out after you select a shorter period in timeline Splunk will run your search with a different time period

0 Karma

rahulrwt23
New Member

Thanks you
It was helpful.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

http://docs.splunk.com/Documentation/Splunk/6.5.2/Search/Usethetimeline

Mouse over and click on the tallest bar or drag your mouse over a cluster of bars in the timeline.
The events list updates to display only the events that occurred in that selected time range. **
The time range picker also updates to the selected time range.
**You can cancel this selection by clicking Deselect.

it looks like Selecting and Deselecting are so instant, i think, splunk does not run a new search. it got some mechanisms to drill down the selected timeline bars.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

rahulrwt23
New Member

thanks
it was helpful

0 Karma

niketn
Legend

@rahulrwt23, could you please let me know what is this required for? what is your use case?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...