Allow me to choose the 'width' of each time bar in 'results over time' facet / time control
Now it automatically adjusts - i.e. when looking at 7 days, each bar becomes 6 hours. It would be nice to decide what interval to choose.
6 hours is an odd interval. If I am looking at 7 days I would rather see how many of those results are there each day/24 hrs intervals/buckets.
If I am querying 1 or 2 days, I probably want to see a hourly breakdown.
The idea is to offer a drop down to allow selecting specific aggregation intervals.
Thanks for offering this feature. Currently the plan is to upgrade the portal with many new features, the timeline is being re-designed as part of it.
Until that, I can only recommend you to use the query to generate charts that describe this in the manner that fits your data best.
We’ve recently upgraded the query language. Here’s an example of the new syntax, using 3-hour bins over the last two days of events:
| where TimeGenerated > now(-2d)
| summarize count() by bin(TimeGenerated, 3h)
| render timechart