Dashboards & Visualizations

How to force timechart to display zero for null values?

mikefoti
Communicator

I'd like to display the "user count" on a timechart over a 30 day period such that even when only a single day has a count above zero, my line graph will still look like a colored line moving along the base of the x axis until a single spike appears on the day there was a count about zero. Without this, I simply get a dot on a blank page.

I could use a bar graph, but even so, it provides no perspective since the left and right limits (day1 and day 30) dont even show a date value


my search...


index=myindex
action="what im looking for"
| bin span=1d _time 
| stats DC(user) as "user_count" by _time

Labels (1)
0 Karma
1 Solution

yeahnah
Motivator

HI @mikefoti 

Try using the timechart command instead, I think it will fix your issues

index=myindex action="what im looking for"
| timechart span=1m DC(user) as "user_count"

 
Hope this helps

View solution in original post

srauhala_splunk
Splunk Employee
Splunk Employee

In the settings of the visualization you can choose to set 0 for null values. 

 

0 Karma

yeahnah
Motivator

HI @mikefoti 

Try using the timechart command instead, I think it will fix your issues

index=myindex action="what im looking for"
| timechart span=1m DC(user) as "user_count"

 
Hope this helps

Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...