Dashboards & Visualizations

Conditional timechart condiftion

gjhaaland
Explorer

Hi,

Not sure how to fix it. Hope someone can give me a hint.  The code looks like

index=asa host=1.2.3.4 src_sg_info=*

| timchart span=10m dc(src_sg_info) by src_sg_info

| rename user1 as "David E"

 

This splunk code will give a list with active/logged on VPN user.  So far so good. So my question is following: howto  include empty src_sg_info into the same timechart and mark it as "No active VPN user"

Labels (1)
0 Karma

gjhaaland
Explorer

Thanks, is it possible to 

if field src_sg_info does not exist then "No active VPN user" in the same timechart. 

0 Karma

FelixLeh
Contributor

 

index=asa host=1.2.3.4 
| fillnull src_sg_info value="No active VPN user"
| timechart span=10m dc(src_sg_info) by src_sg_info
| rename user1 as "David E"

 

0 Karma

gjhaaland
Explorer

Thanks,

Does not work.  Also know following. If  src_sg_info does not exist then we know that it's no active VPN user. Does not know how to test src_sg_info existance.  Thnaks again. 

 

Rgds

Geir

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...