In your chart the syntax would look like this:
| chart useother=f usenull=f
I tried making minimum size to 0 and that worked.
Thank you.
You may be able to add "NOT index=OTHER" to the search criteria.
having useother=f works for me here, though.
I also was seeing NULL entries and added "AND index=*" to get rid of them.
NOT index=OTHER
will not work unless there is actually an index named "OTHER"
thank you.
You have to use chart
instead of stats
.
This doesnt work for me, no matter what I do it will always display the Other field only on the Pie Chart and not as a Field in the results.
Im using Splunk V4.3.2, is there a fix for this?
I have this same issue with Pie chart. I'm using Splunk 6.2. usenull=f with Chart command still shows "other" slice. And the Not index=OTHER gives syntax errors. Any ideas?
So the command is
index=xyz exception | chart count(exception_message) by exception_message useother=f