Splunk Search

Does the timeline have any zoom limitations in the search bar?

Shuhei052492
Path Finder

Hi Splunker,

This is just my curiosity.

I have a lot of logs that are 99,999 in 1 millisec.

I have tried zooming in until the minimum and then I have understood that 1ms is the limit of zoom.

I think the product specification, but there is no doc to be written about it.

If someone know doc or answers, please let me know.

Regards,

Tags (3)
0 Karma
1 Solution

lstewart_splunk
Splunk Employee
Splunk Employee

As @niketnilay mentions, the smallest unit that you can zoom in to on the timeline is 1 millisecond.

Thank you for pointing out that you could not find any documentation about this.

I have added this information to the documentation here: https://docs.splunk.com/Documentation/Splunk/latest/Search/Usethetimeline#Zoom_in

View solution in original post

lstewart_splunk
Splunk Employee
Splunk Employee

As @niketnilay mentions, the smallest unit that you can zoom in to on the timeline is 1 millisecond.

Thank you for pointing out that you could not find any documentation about this.

I have added this information to the documentation here: https://docs.splunk.com/Documentation/Splunk/latest/Search/Usethetimeline#Zoom_in

niketn
Legend

@Shuhei052492 as you have observed, the smallest unit of time represented as column in the Splunk Search Timeline View seems to be 1 millisecond. The same is also available as Time Picker input as smallest time unit precision.

I have submitted a feedback to the Splunk documentation to capture this.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

Shuhei052492
Path Finder

Hi Niket Nilay,
Thank you for your additional view.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...