Splunk Search

Modifying Timeline Scale

g3s1oa
Explorer

Is there a way to specify the scale of the time chart when performing a search.

For instance, if you perform a search over 4 hours it seems to set the scale of each bar to 1 hour, but below 4 hours and it sets the scale to minutes.... I'd like to perform a search that is over the last 24 hours with each timeline bar equal to 1 minute.

Thanks! -Matt

Tags (1)
0 Karma

coolburner1337
New Member

push

We have the same need. Please help! It's urgent 😕

Kind regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're responding to a thread that is more than six years old so it's unlikely to get a reply. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

donleedman
New Member

is there any update to this. It would be a good thing to be able to adjust the flash timechart based on what time scale I want.

0 Karma

ftk
Motivator

Take a look at the documentation for the timechart command. You can define the bucketing you want using the span parameter as such:

your search | timechart span=1m count by my_field
0 Karma

ftk
Motivator

To my knowledge there is no way to modify that, as the time ranges and spans are calculated on the fly based on the timespans displayed.

0 Karma

g3s1oa
Explorer

Yes, sorry for the confusion. I'm talking about the flash timechart at the top of the results screen and below the query bar. Is there a way to modify that?

0 Karma

ftk
Motivator

Oh, are you talking about the flash timechart that is displayed every time you do a search? The timechart command is a reporting command.

0 Karma

g3s1oa
Explorer

That seems to replace the results with the count of the number of events for each minute... Can I keep the individual results in the main viewing window, but change the timeline granularity?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...