Timeline

Reference topic describing the Timeline page.

The Timeline acts as the homepage of your Splunk On-Call instance. The layout of the Timeline is designed to help you surface pertinent incident information quickly, improve usability, and decrease overall time to resolution.

View incidents and incident tabs

All alerts and activity can be found in the Timeline. For a more organized view, the Incidents pane allows you to view incidents based on who they belong to and their current state: triggered, acknowledge, or resolved.

All incident and alert messages derived from integrated monitoring tools in the Timeline and the Incidents pane include their respective logos to help you rapidly identify the source of an alert. Manually created incidents, along with alerts and incidents originating from the email endpoint or the REST API integrations, will remain logo free.

Incident alerts include the logo of the monitoring tool and the current state.

View incident details

Access incident details directly from the Timeline by selecting Incident Details. This will expand the incident and its event history in the Incidents pane. Quickly identify responsible parties during a firefight by easily seeing which policies are being paged.

You can also find annotation and alert counts to the bottom left-hand corner of the incident card. Selecting the Annotations count opens the Annotations tab of the incident pane.

Selecting Detail will expand the incident details.

Filter the timeline

There are multiple ways to filter the timeline to only show events and messages of interest to you. Here’s how to filter:

  • All Filters: Selecting this option displays a drop-down with options to filter the timeline by route key or message type. Splunk On-Call will remember which options you select so your choices persist between sessions.

  • Delivery insights quick filter: Selecting this filter, which works like an on-off button, will filter the timeline for only delivery insights message types. All other message types will be hidden.

  • Chat quick filter: Selecting this filter, which works like an on-off button, will filter the timeline for only chat messages. This is useful when you’re trying to follow a conversation in the timeline. It removes all other events so chats are streamlined.

The delivery insights and chat quick filters can’t be used simultaneously. If one filter is on, selecting the other filter turns the first off. The filter icon will turn blue when it’s active. Filter selections under All Filters will be disregarded when a quick filter is on.

There are several filter options.

Customize the timeline view

You can customize your Splunk On-Call homepage to include or exclude what is most important to you. For example, if you would prefer to only see the Timeline and Incidents pane, you can deselect the People pane.You can customize your view to display only the information you want to see.