Timeline
The Timeline tab presents data and events that span a period of up to 30 days in various sections.
The timeline color conventions facilitate spotting issues. Events in red are a quick indicator of underperforming metrics and problems.
The following sections explain which chronological device events are shown in each category.
Alerts and errors
Shows alert events, error events, freeze events.
Freezes
By default, the timeline shows user-impacting freeze events — application freezes that occurred while the application was in the foreground on an unlocked device.

Select a freeze event to open the right-side panel. The panel shows:
The name and version of the frozen application.
Freeze duration: how long the application was unresponsive.
Freeze end reason: how the freeze resolved:
recovered — the application became responsive again.
crashed — the application exited with a crash.
terminated — the user stopped the application, for example through Task Manager, while it was still unresponsive.
session ended — the user logged off or the session was locked while the application was still unresponsive.
unknown — the end reason could not be determined.
Use the Suggested investigations links to view freeze history for the binary or all freeze events in the past 24 hours.
Freeze events are available on Windows only and require Collector version 26.6 or above.
Device performance
Shows CPU, memory usage, system drive space, GPU, NPU, and disk performance. Events are shown in 5-minute intervals.
Thresholds for Device Performance metrics align with DEX score thresholds. Refer to Device view timeline metric thresholds.
The NPU metric are available only for devices running Windows.
CPU
By default, the timeline shows the normalized CPU usage:

Select an event on the timeline to drill down to it. The timeline drill down panel opens on the right side, where you can select the metrics and binaries that contribute to the CPU usage.
Here you can:
Identify tasks waiting for the CPU by selecting CPU queue length to open its metric-specific timeline.
Identify if the CPU is throttled and running below its rated speed by selecting CPU frequency ratio UI label to open its metric-specific timeline.
Identify CPU load caused by drivers by selecting Deferred procedure calls (DPC) from the Hardware and kernel/drivers section to overlay it on the CPU timeline.
Identify which application is driving CPU load by selecting a binary to add its chart to the Normalized CPU usage timeline.

CPU frequency ratio and DPC require Collector version 26.5 or above and are available on Windows only.
Memory
By default, timeline shows overall memory usage:

Select an event on the timeline to drill down to it. The timeline drill down panel opens on the right side, where you can see detailed metrics about the memory usage.
For Windows devices, two separate timelines open up for Memory swap rate and Disk queue length:

For macOS devices, two separate timelines open up for Memory pressure and Memory swap rate:

Memory pressure for macOS requires Collector version 25.8 or higher.
GPU
By default, the timeline shows the GPU usage.

Select an event to drill down. The timeline drill down panel opens on the right side, where you can see the GPU name, the usage percentage at the selected time, and the applications contributing to the GPU load with their individual usage. On devices with multiple GPUs, the panel identifies which GPU is in use.

Here you can:
Select an application from the panel to overlay its individual GPU usage on the timeline.
Viewing contributing applications for GPU requires Collector version 26.3 or above and is available on Windows only.
NPU
By default, the timeline shows the NPU usage — the processing load from AI inference workloads running on the device.

Select an event to drill down. The timeline drill down panel opens on the right side, where you can see the NPU usage percentage at the selected time and the applications contributing to the NPU load with their individual usage.

Here you can:
Select an application from the panel to overlay its individual NPU usage on the timeline.
Viewing contributing applications for NPU requires Collector version 26.3 or above and is available on Windows only.
Connectivity
Shows Wi-Fi and ethernet in 5-minute intervals. Furthermore shows connections, network applications, and connectivity applications in 15-minute intervals.
Collaboration
Shows Microsoft Teams, Zoom calls and any applications configured under the Collaboration category.
Activity
Shows boots and suspends, remote actions, installation and uninstallation of packages and Windows services, configuration changes, Microsoft Teams and Zoom calls (duration of the call).
Boots and suspends
The Boots & suspends row shows power transition events for the device, including full boots, fast startup resumes, resumes from hibernate and sleep, suspends, and power-off events.

Boots and suspends events are available on Windows only and require Collector version 25.8 or above.
Applications
Shows network, desktop and web application usage and events in 15-minute intervals. Refer to the Getting started with Applications documentation for more information about application type.
User interaction
Shows user interaction, login, logout, locks, unlocks, virtual session events such as Citrix RTT and session network latency in 5-minute intervals.
Workflow executions
Shows workflows and remote actions in 15-minute intervals.
Zooming in and out of the timeline
To zoom in on a specific section of the timeline from the Device View page, choose one of these options:
Click on the zoom-in or zoom-out buttons to load up to 48 hours of data into the timeline.
Drag your cursor along the timeline to select the desired timeframe. Narrow the data down to a six-hour timeframe.
Click on the home buttons to adjust the timeline to the events of the device's last seen date and time, i.e., the date and time of the last device activity received by the Nexthink instance.

Drilling down to specific events in the timeline
Hover over a specific event to display its information details. Both the pop-over and the right-side panel visually indicate, with colored icons, the underperforming metrics contributing to the device issue.
Select a specific event to display the selected information details in the right-side panel within the device icon. The information includes device performance, connectivity, activities, application usage, and links to relevant dashboards and Suggested investigations.
Additionally, the Actions icon in the right-side panel allows you to take associated actions from the Device View page on the target device, depending on the user role permissions.

Refer to the Using Device View for call quality issues documentation to leverage the Timeline tab for troubleshooting collaboration tools.
Obtaining binary descriptions from the Timeline side panel
From the Timeline side panel, hover over any binary name to obtain an AI-generated description.
These binary descriptions attempt to attribute a category and subcategory to the binary, providing additional context related to functionality.

The system displays the ✦ sparkles icon to indicate AI-generated content or insights. AI is evolving rapidly and delivering great insights, but it can still make mistakes. Nexthink recommends validating your results to ensure accuracy and support informed decision-making.
Refer to the Nexthink Insights - AI Model Card documentation for more information.
RELATED TOPICS:
Last updated
Was this helpful?