Why does the timeline go away when you aggregate the data with commands like stats? Can we get it back? It used to be there in version 4, but now that we upgraded to version 5 a couple of weeks ago it vanishes from the screen when you aggregate the data.
From version 5.0, there are three type of modes to search events. The default mode is smart. It will remove timeline and get result faster. If you want to see timeline, please select verbose mode. You can also refer to following docs.
Hope this help.
http://docs.splunk.com/Documentation/Splunk/latest/Search/Changethesearchmode
From version 5.0, there are three type of modes to search events. The default mode is smart. It will remove timeline and get result faster. If you want to see timeline, please select verbose mode. You can also refer to following docs.
Hope this help.
http://docs.splunk.com/Documentation/Splunk/latest/Search/Changethesearchmode