Dashboards & Visualizations

How to force timechart to display zero for null values?

mikefoti
Communicator

I'd like to display the "user count" on a timechart over a 30 day period such that even when only a single day has a count above zero, my line graph will still look like a colored line moving along the base of the x axis until a single spike appears on the day there was a count about zero. Without this, I simply get a dot on a blank page.

I could use a bar graph, but even so, it provides no perspective since the left and right limits (day1 and day 30) dont even show a date value


my search...


index=myindex
action="what im looking for"
| bin span=1d _time 
| stats DC(user) as "user_count" by _time

Labels (1)
0 Karma
1 Solution

yeahnah
Motivator

HI @mikefoti 

Try using the timechart command instead, I think it will fix your issues

index=myindex action="what im looking for"
| timechart span=1m DC(user) as "user_count"

 
Hope this helps

View solution in original post

srauhala_splunk
Splunk Employee
Splunk Employee

In the settings of the visualization you can choose to set 0 for null values. 

 

0 Karma

yeahnah
Motivator

HI @mikefoti 

Try using the timechart command instead, I think it will fix your issues

index=myindex action="what im looking for"
| timechart span=1m DC(user) as "user_count"

 
Hope this helps

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...