Read the timeline
Read every source on one time axis, with each event drawn at its clock error. Find the findings and see where two events are too close to order. Zoom from a whole run down to a few milliseconds.
On this page9
The timeline is the center of the Reconstruction tab. It gives each source a lane on one UTC axis and draws every event with the clock error it carries. You see what came first and where the logs cannot say. This page reads INC-0142 from the example dataset, in which a process was killed, a topic stalled and the ground stopped hearing the vehicle.
Before you start#
- Open an incident on its Reconstruction tab. See Work an incident.
- Anyone who can inspect original evidence can read the timeline.
Read it step by step#
Read the toolbar
The toolbar gives the window on screen, such as 14:31:53.000 to 14:32:16.000, 23 s. Then come Zoom out and Zoom in, then Fit incident and Whole run. Fit incident returns to the incident window.
The UTC and Elapsed switch changes the axis. Elapsed times count from the start of the log, so the kernel kill in INC-0142 sits at T+18:44.716.
Read the rows
The axis row is labeled UTC, 24 Sep 2026, or Elapsed from log start. Below it, the Findings row holds the rule results, with Rule results and a count: 6 in INC-0142. One lane per source follows, labeled with the source, a subtitle and its bound.
Lane Subtitle Label shows Flight controller 14_13_19.ulg ±40 ms Altitude above launch The value at the crosshair Battery battery_status The value at the crosshair Companion journal uas04-orin, 5 units ±6 ms Process samples perception_node RSS ±6 ms Ground receive sysid 4, 1 Hz ±15 ms A companion clock that never synchronized gets its own group of lanes. See The companion clock group.
Find the findings
Each finding that is not dismissed puts a flag in the Findings row, with a guide line down to its event. Flags within 14 px of each other join one cluster. Its label is the first finding's short name followed by , and N more.
Hover a cluster for the number of findings and the time they span, then Click to zoom in. A single flag reads Click to inspect and selects its event. A cluster drawn in the warning style, with the order-unknown glyph, holds two events whose order is unknown. Their overlap is too narrow to draw at this zoom. The cluster's tooltip adds Contains events whose order is unknown.
Check an order
Zoom in on two events from different clocks. Each carries a bracket as wide as its clock error. Where the intervals of two events overlap, the plot hatches the overlap across both lanes and labels it Order unknown.
In INC-0142, Show the first pair in the clock note takes you there. It opens on the last
obstacle_distancesample at 14:32:04.079 ±40 ms and the kernel kill at 14:32:04.118 ±6 ms. They are 39 ms apart against a 46 ms combined bound, so Foxborne claims no order between them.Example dataThe order-unknown pair in INC-0142. The flight log's bracket reaches past the kill, so neither event can be placed first. Scrub with the crosshair
Move the pointer over the lanes. A crosshair follows it with the time, and each channel label shows its value at that moment, highlighted past its threshold. The map and the vehicle diagram follow the pointer too.
Hover an event for its title, time and bound. On the heartbeat gap in INC-0142 the tooltip reads 14:32:04.912 UTC, ±15 ms plus up to 412 ms latency.
Select and step
Select an event to open the evidence inspector. A cursor line and a time pill mark the event at the top of the plot. ← and → step to the previous or next event on the same clock.
Marks on the plot#
| Mark | What it means |
|---|---|
| A vertical tick | One event. Red for journal priority 3 (error) or more severe, amber for priority 4 (warning) |
| A tick with a square head | A finding |
| A larger head and a shaded band | The selected event. The band covers its whole error and latency range |
| A bracket with end caps | The event's clock error, drawn once it is at least 3 px wide |
| A dashed line left of the bracket | Link latency on a receive record. It reaches only to the left, because a packet arrives after it was sent |
| A hatched block | No data, labeled when it fits: No telemetry received for 6.96 s, No obstacle_distance for 7.5 s |
| A banded strip on the flight controller lane | The navigation state, such as Disarmed, Takeoff, Mission, Hold, Return and Landed. Hold and Return use a second style |
| A line with dots | A series, such as perception_node RSS. Dots appear when samples are at least 5 px apart. The line breaks at a gap over 1.6 s, or where the process ID changes |
| A channel with a scale | A value from the flight log, such as Altitude or Battery, with its scale minimum and maximum. Channels break at gaps over 5 s |
| A threshold line | Above 24 m/s² or Below 8 on a channel, Threshold 6,144 MiB on process samples. The trace is highlighted where the value crosses it |
| A shaded span | A labeled stretch, such as jamming_state 3 on the Jamming indicator lane of INC-0141 |
| A rug of short ticks | One tick per message received at range control |
| A hatch across two lanes | Order unknown: the overlap of two events' intervals |
In INC-0142 the process samples line breaks at the kill and starts again as pid 3398, the restarted perception_node.
Zoom and pan#
| To | Do this |
|---|---|
| Zoom in or out | Zoom in and Zoom out, or ] and [. The zoom centers on the selected event when it is in view, otherwise on the middle of the window |
| Zoom at the pointer | Hold ⌘, Ctrl or Alt and scroll. Up zooms in, down zooms out |
| Return to the incident window | Fit incident or F |
| See the whole run | Whole run |
| Pan | Drag inside the window box on the whole-run strip |
| Resize the window | Drag either edge of the window box |
| Jump elsewhere | Press the strip outside the box. The window centers there |
| Zoom into a cluster | Select the cluster |
The window stays inside the run and never gets narrower than 40 ms. A plain scroll moves the page, not the timeline.
The whole-run strip, labeled Whole run, sits under the plot. It shows the navigation bands and every aligned event, with findings drawn taller. Everything outside the window is dimmed, and the window is a box with a handle at each end.
The companion clock group#
When the companion clock never synchronized, the journal and process samples sit below a Companion clock divider, subtitled Not aligned, own axis. Across the plot, the divider reads Own clock. No order is claimed against the lanes above.
The group keeps its own axis in the companion's own time, and its lanes show No anchor in place of a bound. The crosshair does not enter it. The zoom buttons and keys scale it by the same factor as the main axis, and Fit incident resets it.
After a manual alignment, the subtitle reads Aligned by hand, ±1.04 s and the divider Mapped onto UTC by a manual alignment. Error bounds include ±1.04 s. The companion lanes then carry ±1.05 s: their own 6 ms plus the 1,040 ms alignment bound. See Align a clock by hand.
Legend#
The footer reads Finding, Event, Clock error, Link latency, No data and Order unknown. On the right it reminds you: Hold ⌘ or Alt and scroll to zoom.
Check the result#
At the INC-0142 incident window, you can read the failure in order:
- The process samples line crosses 6,144 MiB at 14:32:01.204.
- At 14:32:04, the flight controller's last
obstacle_distancesample and the kernel kill share a hatched Order unknown. - The receive rug stops after 14:32:03.912, and No telemetry received for 6.96 s fills the lane until 14:32:10.874.
Troubleshoot#
Scrolling moves the page. Hold ⌘, Ctrl or Alt while you scroll to zoom the timeline.
An event has no bracket. At this zoom its bound is narrower than 3 px. Zoom in, or read the bound in the inspector.
A flag has no label. There was no room for it near the flag. Hover the flag, or zoom in.
The clock note counts order-unknown pairs, but no hatch shows. The overlaps are too narrow to draw at this zoom. Use Show the first pair, or select a cluster that carries the order-unknown glyph.
Companion events have no crosshair and no place on the map. They are on the companion's own clock. Align it by hand if a matching pair of events exists.