Timeline and events

Below the search bar and search controls is the timeline. When the Events tab is selected, this visually depicts the number of events observed for each incremental period of time; the time period represented by each time column is automatically adjusted depending on the time range selected in the time-range picker. Peaks, valleys, and gaps observed in the timeline indicate changes in activity or server downtime; if you are using one or more search filters, you can see when events occurred that match the filter.

If you click the Patterns tab, you can see the results of some behind-the-scenes analysis Splunk does using the cluster command to identify common characteristics in the returned events this can be useful for ...

Get Splunk 7.x Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.