Splunk Search

Modifying Timeline Scale

g3s1oa
Explorer

Is there a way to specify the scale of the time chart when performing a search.

For instance, if you perform a search over 4 hours it seems to set the scale of each bar to 1 hour, but below 4 hours and it sets the scale to minutes.... I'd like to perform a search that is over the last 24 hours with each timeline bar equal to 1 minute.

Thanks! -Matt

Tags (1)
0 Karma

coolburner1337
New Member

push

We have the same need. Please help! It's urgent 😕

Kind regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're responding to a thread that is more than six years old so it's unlikely to get a reply. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

donleedman
New Member

is there any update to this. It would be a good thing to be able to adjust the flash timechart based on what time scale I want.

0 Karma

ftk
Motivator

Take a look at the documentation for the timechart command. You can define the bucketing you want using the span parameter as such:

your search | timechart span=1m count by my_field
0 Karma

ftk
Motivator

To my knowledge there is no way to modify that, as the time ranges and spans are calculated on the fly based on the timespans displayed.

0 Karma

g3s1oa
Explorer

Yes, sorry for the confusion. I'm talking about the flash timechart at the top of the results screen and below the query bar. Is there a way to modify that?

0 Karma

ftk
Motivator

Oh, are you talking about the flash timechart that is displayed every time you do a search? The timechart command is a reporting command.

0 Karma

g3s1oa
Explorer

That seems to replace the results with the count of the number of events for each minute... Can I keep the individual results in the main viewing window, but change the timeline granularity?

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...