Splunk Search

Flashtimeline not showing when searching with a groupby i.e. "| stats count by"

benjwarner
Explorer

Hiya,

It seems that since upgrading splunk to v5, any searches which are grouped by a count. e.g.:

“test” | stats count by host

Do NOT show the flashtimeline at the top of the search results.

The flashtimeline DID show on the same queries before our upgrade.

If I remove the count by. E.g. above just search for. e.g.:

“test”

...the flashtimeline does display.

Any advice would be appreciated.

Tags (2)
0 Karma

benjwarner
Explorer

I've been talking to splunk about this, and they have provided an answer that I will share here.

There is a dropdown up the top which has the three options. "Smart", "Fast" or "Verbose". Selecting "Verbose" ensures that the flashtimeline is displayed.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...