<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to force graph to include recent &amp;quot;zero&amp;quot; values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130210#M35456</link>
    <description>&lt;P&gt;So I have this basic search for a line graph visualization:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(search goes here) | timechart count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Let's say I've had 10 events/hour up until 7:00am this morning.  Between 7:00-10:00am I've had zero events.  When I render the graph, it "stops" at 7:00am.  How can I force the graph to include the zero events between 7:00-10:00am?  The reason this is important is that I'm trying to get the graph to communicate that the events have stopped... but it looks like they are still on-going since it doesn't include recent hours of zero events.  I hope that makes sense.&lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/timechart.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jul 2014 16:06:58 GMT</pubDate>
    <dc:creator>echojacques</dc:creator>
    <dc:date>2014-07-03T16:06:58Z</dc:date>
    <item>
      <title>How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130210#M35456</link>
      <description>&lt;P&gt;So I have this basic search for a line graph visualization:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(search goes here) | timechart count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Let's say I've had 10 events/hour up until 7:00am this morning.  Between 7:00-10:00am I've had zero events.  When I render the graph, it "stops" at 7:00am.  How can I force the graph to include the zero events between 7:00-10:00am?  The reason this is important is that I'm trying to get the graph to communicate that the events have stopped... but it looks like they are still on-going since it doesn't include recent hours of zero events.  I hope that makes sense.&lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/timechart.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 16:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130210#M35456</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2014-07-03T16:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130211#M35457</link>
      <description>&lt;P&gt;The visualization for timechart has an option for how to treat "missing" values. The default setting is "gap", which means "if you have no events, don't draw a line".&lt;/P&gt;

&lt;P&gt;You want the option called "treat as zero".&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 16:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130211#M35457</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-07-03T16:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130212#M35458</link>
      <description>&lt;P&gt;Hi, thanks for the reply.  I've tried that option and while it works for events between let's say 6:00am yesterday and 7:00am today, it doesn't force the graph to draw a line for the most recent X hours.  So right now, even with that option set, my graph stops at 7:00am this morning even though it's 10:30am.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 16:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130212#M35458</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2014-07-03T16:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130213#M35459</link>
      <description>&lt;P&gt;I've added my timechart in my original post.  You'll see that while it successfully draws a line at zero for previous times, the line ends at 7:20am and doesn't drop down to zero for the previous 3 hours (to 10:30am).  It's still dangling high at 100 even though the current value for this event is zero, and has been for the last 3 hours.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 16:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130213#M35459</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2014-07-03T16:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130214#M35460</link>
      <description>&lt;P&gt;Try this workaround&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search | timechart count | appendpipe [|stats count | addinfo | eval _time=info_max_time | table _time] | makecontinuous
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 03 Jul 2014 17:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130214#M35460</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-03T17:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130215#M35461</link>
      <description>&lt;P&gt;You could also try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | timechart count fixedrange=T | fillnull
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;although fixrange is supposed to be the default.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 18:00:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130215#M35461</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-07-03T18:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130216#M35462</link>
      <description>&lt;P&gt;I just tried this and unfortunately, it produces the same result.  Instead, is there a way to force a time range (e.g. last 24 hours) in a graph?&lt;/P&gt;

&lt;P&gt;In my opinion, this is almost a bug as this should be a simple/basic thing to do...&lt;/P&gt;

&lt;P&gt;Or maybe I shouldn't be using a timechart for what I'm trying t do?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 18:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130216#M35462</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2014-07-03T18:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130217#M35463</link>
      <description>&lt;P&gt;I tried this, and while this does get the graph to hit zero, the trend line is still very much compressed -&amp;gt; I've had zero events for this search in the last 6 hours, so while the line goes to zero, there is no continuation/trend of the line for the last 6 hours (it looks like the events just now stopped and went to zero, which is not the case).&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 18:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130217#M35463</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2014-07-03T18:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130218#M35464</link>
      <description>&lt;P&gt;Try the updated answer. This ensures that all the missing bins (e.g. last 6 hrs in your search) will have be shown and you'll get more streamlined graph.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 19:11:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130218#M35464</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-03T19:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to force graph to include recent "zero" values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130219#M35465</link>
      <description>&lt;P&gt;Thanks, the updated answer works!  I really appreciate it, I probably would not have figured this out on my own.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 19:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-force-graph-to-include-recent-quot-zero-quot-values/m-p/130219#M35465</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2014-07-03T19:44:20Z</dc:date>
    </item>
  </channel>
</rss>

