Search queries executed by XpoSearch return the following:
XpoSearch returns a graph that shows the distribution of events over time. You can choose how to display the graph and what to show in the graph. You can also view the distribution of the results in a log, zoom in or out of any time slot, and view the previous or next timeslot.
XpoSearch enables you to define what your graph looks like, as well as its contents, using the icons on the Graph Toolbar.
You have the option of displaying your graph as a bar graph (the default) or a line graph. In the bar graph, a bar appears at each point in time where events were found to match your search query. The height of each bar represents the number of events that occurred at the specific time. A bar does not appear at times when no events matching your search query occurred. A line graph shows how the number of events matching the search query changes from one point in time to the next.
To display your graph as a bar graph:
To display your graph as a line graph:
You have the option of displaying your graph in a split view or a summary view.
You can zoom into any timeslot in your graph, so that you can see a more detailed breakdown of events over a smaller period of time. For example, a search executed for a time period of seven days shows the distribution of events that match the search criteria, per day. You can then zoom into any timeslot (day) to see the distribution of events during that day, and you can zoom in further to see the distribution of events in a specific hour on that day. At any point, you can zoom out repeatedly until you reach the graph resulting from the time period that you selected for the search query.
To zoom into a timeslot:
You can display the previous or next timeslot directly from the graph.
To display the previous timeslot:
To display the next timeslot:
XpoSearch enables you to view detailed stack trace information of all resulting events, provided that the events have stack traces. This feature makes it possible for you to see the cause of any event. You can also close the stack traces of all events.
By default, while XpoSearch searches for all events that match your search query, it also performs analytics on all events, colorcoding the fields according to their severity, and displaying the severity of the event. You can disable analytics, so that XpoSearch only performs the search.