Splunk 4.3
Search :
index=server1 | table processName porcessCount
result A : search has a results.
processName processCount
java 14
vi 2
result B : search has no results.
No results found, inspector...
How can i display it below...
processName processCount
No Process
Thanks.
Hi joy76,
Take a look at this answer http://answers.splunk.com/answers/176466/how-to-use-eval-if-there-is-no-result-from-the-bas.html
Hope this helps ...
cheers, MuS