Splunk Search

Modifying Timeline Scale

g3s1oa
Explorer

Is there a way to specify the scale of the time chart when performing a search.

For instance, if you perform a search over 4 hours it seems to set the scale of each bar to 1 hour, but below 4 hours and it sets the scale to minutes.... I'd like to perform a search that is over the last 24 hours with each timeline bar equal to 1 minute.

Thanks! -Matt

Tags (1)
0 Karma

coolburner1337
New Member

push

We have the same need. Please help! It's urgent 😕

Kind regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You're responding to a thread that is more than six years old so it's unlikely to get a reply. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

donleedman
New Member

is there any update to this. It would be a good thing to be able to adjust the flash timechart based on what time scale I want.

0 Karma

ftk
Motivator

Take a look at the documentation for the timechart command. You can define the bucketing you want using the span parameter as such:

your search | timechart span=1m count by my_field
0 Karma

ftk
Motivator

To my knowledge there is no way to modify that, as the time ranges and spans are calculated on the fly based on the timespans displayed.

0 Karma

g3s1oa
Explorer

Yes, sorry for the confusion. I'm talking about the flash timechart at the top of the results screen and below the query bar. Is there a way to modify that?

0 Karma

ftk
Motivator

Oh, are you talking about the flash timechart that is displayed every time you do a search? The timechart command is a reporting command.

0 Karma

g3s1oa
Explorer

That seems to replace the results with the count of the number of events for each minute... Can I keep the individual results in the main viewing window, but change the timeline granularity?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...