Splunk Search

Deselect option in timeline.

rahulrwt23
New Member

What 'Deselect' option in the timeline will do? Will it run the new search or not?

Tags (1)
0 Karma

Javip
Path Finder

I suppose you mean when you do a selection on timeline in search page, only if you click on "Zoom to Selection" this filters temporary your initial query and you can visualize only events inside your new selected period of time. "Deselect" option only deactivates your selection in timeline and it doesn't run you query.

Only in case you zoom in or zoom out after you select a shorter period in timeline Splunk will run your search with a different time period

0 Karma

rahulrwt23
New Member

Thanks you
It was helpful.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

http://docs.splunk.com/Documentation/Splunk/6.5.2/Search/Usethetimeline

Mouse over and click on the tallest bar or drag your mouse over a cluster of bars in the timeline.
The events list updates to display only the events that occurred in that selected time range. **
The time range picker also updates to the selected time range.
**You can cancel this selection by clicking Deselect.

it looks like Selecting and Deselecting are so instant, i think, splunk does not run a new search. it got some mechanisms to drill down the selected timeline bars.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

rahulrwt23
New Member

thanks
it was helpful

0 Karma

niketn
Legend

@rahulrwt23, could you please let me know what is this required for? what is your use case?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...