Splunk Search

Modifying Timeline Scale

g3s1oa
Explorer

Is there a way to specify the scale of the time chart when performing a search.

For instance, if you perform a search over 4 hours it seems to set the scale of each bar to 1 hour, but below 4 hours and it sets the scale to minutes.... I'd like to perform a search that is over the last 24 hours with each timeline bar equal to 1 minute.

Thanks! -Matt

Tags (1)
0 Karma

coolburner1337
New Member

push

We have the same need. Please help! It's urgent 😕

Kind regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're responding to a thread that is more than six years old so it's unlikely to get a reply. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

donleedman
New Member

is there any update to this. It would be a good thing to be able to adjust the flash timechart based on what time scale I want.

0 Karma

ftk
Motivator

Take a look at the documentation for the timechart command. You can define the bucketing you want using the span parameter as such:

your search | timechart span=1m count by my_field
0 Karma

ftk
Motivator

To my knowledge there is no way to modify that, as the time ranges and spans are calculated on the fly based on the timespans displayed.

0 Karma

g3s1oa
Explorer

Yes, sorry for the confusion. I'm talking about the flash timechart at the top of the results screen and below the query bar. Is there a way to modify that?

0 Karma

ftk
Motivator

Oh, are you talking about the flash timechart that is displayed every time you do a search? The timechart command is a reporting command.

0 Karma

g3s1oa
Explorer

That seems to replace the results with the count of the number of events for each minute... Can I keep the individual results in the main viewing window, but change the timeline granularity?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...