<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fill nulls based on previous value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138317#M37948</link>
    <description>&lt;P&gt;hi arramack,&lt;BR /&gt;
try add this query &lt;CODE&gt;eval QUALITY= if (quality="Bad",0,' ')&lt;/CODE&gt;in your query for the values of the quality&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="tcp:51112" | eval QUALITY= if (Quality="Bad",0,' ')  | timechart span=1s Max(Value) by Tag | filldown
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 08 Apr 2015 15:33:04 GMT</pubDate>
    <dc:creator>gyslainlatsa</dc:creator>
    <dc:date>2015-04-08T15:33:04Z</dc:date>
    <item>
      <title>Fill nulls based on previous value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138315#M37946</link>
      <description>&lt;P&gt;I have events that contain the following data:&lt;/P&gt;

&lt;P&gt;Time, Name, Value, Quality.&lt;/P&gt;

&lt;P&gt;The Quality value can either be "Good" or "Bad", meaning the measurement was made or not. If Quality is "Bad", then the Value will be 0. Otherwise Value is a number (which can also be 0).&lt;/P&gt;

&lt;P&gt;I am logging the data per second, but only if there is a data change. What I want is a search that always returns a value for every second, even if there is no event in that second.&lt;/P&gt;

&lt;P&gt;If there is no event, then the event must be the same as the previous event logged.&lt;/P&gt;

&lt;P&gt;I have tried to use &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="tcp:51112" | timechart span=1s Max(Value) by Tag | filldown
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but that doesn't show me the Quality. I will also have many tags later on (up to 5000), so then I will have 5000 columns. I don't know if that is very efficient. This will be used for graphing 1-10 Tags at a time.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 14:28:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138315#M37946</guid>
      <dc:creator>arramack</dc:creator>
      <dc:date>2015-04-08T14:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Fill nulls based on previous value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138316#M37947</link>
      <description>&lt;P&gt;Hi arramack,&lt;BR /&gt;
 I think that , if your query doesn't show you the Quality, ist because with &lt;STRONG&gt;filldown&lt;/STRONG&gt; command,  If there were not any previous values for a field (in this case its &lt;STRONG&gt;Quality&lt;/STRONG&gt; field), it will be left blank (NULL). I refer to Search Reference Manual. Follow the link that follow:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Filldown"&gt;&lt;/A&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Filldown" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Filldown&lt;/A&gt;&lt;BR /&gt;
&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138316#M37947</guid>
      <dc:creator>ngatchasandra</dc:creator>
      <dc:date>2015-04-08T15:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Fill nulls based on previous value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138317#M37948</link>
      <description>&lt;P&gt;hi arramack,&lt;BR /&gt;
try add this query &lt;CODE&gt;eval QUALITY= if (quality="Bad",0,' ')&lt;/CODE&gt;in your query for the values of the quality&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="tcp:51112" | eval QUALITY= if (Quality="Bad",0,' ')  | timechart span=1s Max(Value) by Tag | filldown
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:33:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138317#M37948</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2015-04-08T15:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Fill nulls based on previous value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138318#M37949</link>
      <description>&lt;P&gt;After I run timechart my columns are _time, TagName1, TagName2, TagName3 etc..&lt;/P&gt;

&lt;P&gt;Under the TagName I have the value for each timestamp. &lt;/P&gt;

&lt;P&gt;That's the problem. Timechart completely screws up the table structure. There is no place to put the Quality component.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 17:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138318#M37949</guid>
      <dc:creator>arramack</dc:creator>
      <dc:date>2015-04-08T17:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Fill nulls based on previous value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138319#M37950</link>
      <description>&lt;P&gt;Hi Arramack,&lt;/P&gt;

&lt;P&gt;How about &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TagName= "Your Tag" Value=* | Eval Quality=if(Quality=="good", 192, 0) | timechart  span=1s sum(Value) as Value, sum(Quality) as Quality by TagName | filldown 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/309i3E96A0DB28083543/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;This will only work for one tag but if you couple with a input filed, you can have a dropdown for all 5000 to select them one by one. I am not exactly this is the best way to visualize for so many tags. What you can consider is having clones of the table, i.e. Clone 10 of this table for 10 Tags on your dashboard.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 15:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fill-nulls-based-on-previous-value/m-p/138319#M37950</guid>
      <dc:creator>Stevelim</dc:creator>
      <dc:date>2016-04-21T15:59:28Z</dc:date>
    </item>
  </channel>
</rss>

