timeline

noun

A visual representation of the number of events of events returned by a Splunk search over a chosen time range. The timeline is a type of histogram, where the range is broken up into smaller time intervals (such as seconds, minutes, hours, or days), and the count of events for each interval is displayed in column form.

The timeline is a type of histogram that represents events returned by a specific Splunk over a chosen time range.

The timeline can also display the results of real-time searches, where the timeline represents the sliding "window" of time covered by a real-time search.

Related terms

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time