# Read the timeline

URL: /investigate/timeline

Read every source on one time axis, with each event drawn at its clock error. Find the findings and see where two events are too close to order. Zoom from a whole run down to a few milliseconds.



The timeline is the center of the **Reconstruction** tab. It gives each source a lane on one UTC axis and draws every event with the clock error it carries. You see what came first and where the logs cannot say. This page reads INC-0142 from the example dataset, in which a process was killed, a topic stalled and the ground stopped hearing the vehicle.

## Before you start [#before-you-start]

* Open an incident on its **Reconstruction** tab. See [Work an incident](/investigate/incidents).
* Anyone who can inspect original evidence can read the timeline.

## Read it step by step [#read-it-step-by-step]

<Steps>
  <Step title="Read the toolbar">
    The toolbar gives the window on screen, such as **14:31:53.000 to 14:32:16.000, 23 s**. Then come **Zoom out** and **Zoom in**, then **Fit incident** and **Whole run**. **Fit incident** returns to the incident window.

    The **UTC** and **Elapsed** switch changes the axis. Elapsed times count from the start of the log, so the kernel kill in INC-0142 sits at T+18:44.716.
  </Step>

  <Step title="Read the rows">
    The axis row is labeled **UTC, 24 Sep 2026**, or **Elapsed from log start**. Below it, the **Findings** row holds the rule results, with **Rule results** and a count: 6 in INC-0142. One lane per source follows, labeled with the source, a subtitle and its bound.

    | Lane              | Subtitle             | Label shows                |
    | ----------------- | -------------------- | -------------------------- |
    | Flight controller | 14\_13\_19.ulg       | ±40 ms                     |
    | Altitude          | above launch         | The value at the crosshair |
    | Battery           | battery\_status      | The value at the crosshair |
    | Companion journal | uas04-orin, 5 units  | ±6 ms                      |
    | Process samples   | perception\_node RSS | ±6 ms                      |
    | Ground receive    | sysid 4, 1 Hz        | ±15 ms                     |

    A companion clock that never synchronized gets its own group of lanes. See [The companion clock group](#the-companion-clock-group).
  </Step>

  <Step title="Find the findings">
    Each finding that is not dismissed puts a flag in the **Findings*&#x2A; row, with a guide line down to its event. Flags within 14 px of each other join one cluster. Its label is the first finding's short name followed by **, and** *N* **more**.

    Hover a cluster for the number of findings and the time they span, then **Click to zoom in**. A single flag reads **Click to inspect** and selects its event. A cluster drawn in the warning style, with the order-unknown glyph, holds two events whose order is unknown. Their overlap is too narrow to draw at this zoom. The cluster's tooltip adds **Contains events whose order is unknown**.
  </Step>

  <Step title="Check an order">
    Zoom in on two events from different clocks. Each carries a bracket as wide as its clock error. Where the intervals of two events overlap, the plot hatches the overlap across both lanes and labels it **Order unknown**.

    In INC-0142, **Show the first pair** in the clock note takes you there. It opens on the last `obstacle_distance` sample at 14:32:04.079 ±40 ms and the kernel kill at 14:32:04.118 ±6 ms. They are 39 ms apart against a 46 ms combined bound, so Foxborne claims no order between them.

    <Figure caption="The order-unknown pair in INC-0142. The flight log's bracket reaches past the kill, so neither event can be placed first.">
      <OrderUnknown />
    </Figure>
  </Step>

  <Step title="Scrub with the crosshair">
    Move the pointer over the lanes. A crosshair follows it with the time, and each channel label shows its value at that moment, highlighted past its threshold. The map and the vehicle diagram follow the pointer too.

    Hover an event for its title, time and bound. On the heartbeat gap in INC-0142 the tooltip reads **14:32:04.912 UTC, ±15 ms plus up to 412 ms latency**.
  </Step>

  <Step title="Select and step">
    Select an event to open the evidence inspector. A cursor line and a time pill mark the event at the top of the plot. <Kbd>←</Kbd> and <Kbd>→</Kbd> step to the previous or next event on the same clock.
  </Step>
</Steps>

## Marks on the plot [#marks-on-the-plot]

| Mark                                         | What it means                                                                                                                                                  |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| A vertical tick                              | One event. Red for journal priority 3 (error) or more severe, amber for priority 4 (warning)                                                                   |
| A tick with a square head                    | A finding                                                                                                                                                      |
| A larger head and a shaded band              | The selected event. The band covers its whole error and latency range                                                                                          |
| A bracket with end caps                      | The event's clock error, drawn once it is at least 3 px wide                                                                                                   |
| A dashed line left of the bracket            | Link latency on a receive record. It reaches only to the left, because a packet arrives after it was sent                                                      |
| A hatched block                              | No data, labeled when it fits: **No telemetry received for 6.96 s**, **No obstacle\_distance for 7.5 s**                                                       |
| A banded strip on the flight controller lane | The navigation state, such as Disarmed, Takeoff, Mission, Hold, Return and Landed. Hold and Return use a second style                                          |
| A line with dots                             | A series, such as perception\_node RSS. Dots appear when samples are at least 5 px apart. The line breaks at a gap over 1.6 s, or where the process ID changes |
| A channel with a scale                       | A value from the flight log, such as Altitude or Battery, with its scale minimum and maximum. Channels break at gaps over 5 s                                  |
| A threshold line                             | **Above 24 m/s²** or **Below 8** on a channel, **Threshold 6,144 MiB** on process samples. The trace is highlighted where the value crosses it                 |
| A shaded span                                | A labeled stretch, such as **jamming\_state 3** on the Jamming indicator lane of INC-0141                                                                      |
| A rug of short ticks                         | One tick per message received at range control                                                                                                                 |
| A hatch across two lanes                     | **Order unknown**: the overlap of two events' intervals                                                                                                        |

In INC-0142 the process samples line breaks at the kill and starts again as pid 3398, the restarted perception\_node.

## Zoom and pan [#zoom-and-pan]

| To                            | Do this                                                                                                                                                                  |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Zoom in or out                | **Zoom in** and **Zoom out**, or <Kbd>{']'}</Kbd> and <Kbd>{'['}</Kbd>. The zoom centers on the selected event when it is in view, otherwise on the middle of the window |
| Zoom at the pointer           | Hold <Kbd>⌘</Kbd>, <Kbd>Ctrl</Kbd> or <Kbd>Alt</Kbd> and scroll. Up zooms in, down zooms out                                                                             |
| Return to the incident window | **Fit incident** or <Kbd>F</Kbd>                                                                                                                                         |
| See the whole run             | **Whole run**                                                                                                                                                            |
| Pan                           | Drag inside the window box on the whole-run strip                                                                                                                        |
| Resize the window             | Drag either edge of the window box                                                                                                                                       |
| Jump elsewhere                | Press the strip outside the box. The window centers there                                                                                                                |
| Zoom into a cluster           | Select the cluster                                                                                                                                                       |

The window stays inside the run and never gets narrower than 40 ms. A plain scroll moves the page, not the timeline.

The whole-run strip, labeled **Whole run**, sits under the plot. It shows the navigation bands and every aligned event, with findings drawn taller. Everything outside the window is dimmed, and the window is a box with a handle at each end.

## The companion clock group [#the-companion-clock-group]

When the companion clock never synchronized, the journal and process samples sit below a **Companion clock** divider, subtitled **Not aligned, own axis**. Across the plot, the divider reads &#x2A;*Own clock. No order is claimed against the lanes above.**

The group keeps its own axis in the companion's own time, and its lanes show **No anchor** in place of a bound. The crosshair does not enter it. The zoom buttons and keys scale it by the same factor as the main axis, and **Fit incident** resets it.

After a manual alignment, the subtitle reads **Aligned by hand, ±1.04 s** and the divider &#x2A;*Mapped onto UTC by a manual alignment. Error bounds include ±1.04 s.** The companion lanes then carry ±1.05 s: their own 6 ms plus the 1,040 ms alignment bound. See [Align a clock by hand](/investigate/align-a-clock).

## Legend [#legend]

The footer reads **Finding**, **Event**, **Clock error**, **Link latency**, **No data** and **Order unknown**. On the right it reminds you: **Hold ⌘ or Alt and scroll to zoom**.

## Check the result [#check-the-result]

At the INC-0142 incident window, you can read the failure in order:

* The process samples line crosses 6,144 MiB at 14:32:01.204.
* At 14:32:04, the flight controller's last `obstacle_distance` sample and the kernel kill share a hatched **Order unknown**.
* The receive rug stops after 14:32:03.912, and **No telemetry received for 6.96 s** fills the lane until 14:32:10.874.

## Troubleshoot [#troubleshoot]

**Scrolling moves the page.** Hold ⌘, Ctrl or Alt while you scroll to zoom the timeline.

**An event has no bracket.** At this zoom its bound is narrower than 3 px. Zoom in, or read the bound in the inspector.

**A flag has no label.** There was no room for it near the flag. Hover the flag, or zoom in.

**The clock note counts order-unknown pairs, but no hatch shows.** The overlaps are too narrow to draw at this zoom. Use **Show the first pair**, or select a cluster that carries the order-unknown glyph.

**Companion events have no crosshair and no place on the map.** They are on the companion's own clock. [Align it by hand](/investigate/align-a-clock) if a matching pair of events exists.

## Next [#next]

<Cards>
  <Card title="Alignment and event order" href="/concepts/alignment" icon="layers">
    How two bounds combine and when an order is unknown.
  </Card>

  <Card title="Inspect an event" href="/investigate/event" icon="eye">
    What the inspector shows for a selected event.
  </Card>

  <Card title="Read the map" href="/investigate/map" icon="map">
    Where the vehicle was at each moment of the timeline.
  </Card>

  <Card title="Keyboard shortcuts" href="/reference/keyboard-shortcuts" icon="terminal">
    Every key the console responds to.
  </Card>
</Cards>
