Getting Data In

How do you show all source types even if no data is available?



I'm trying to show all the source types within the last 24 hours (I set that by using presets), and if those source types have no data, I still want to show the name of the soucetype but with 0 (represent no data).

This is what I'm doing now, but it only shows the source types with data for the last 24 hours.

index=* |chart count over sourcetype 
|eval name=if(count=="0", "0", "1") 

Please help. I searched everywhere and tried so many things but still no luck. Also, I'm trying to use the trellis visualization to represent those source types

0 Karma

Ultra Champion

use the | metadata command

| metadata type=sourcetypes index=*
| eval diff=now()-lastTime | where diff > 3600*24
| convert ctime(lastTime) 
| convert ctime(firstTime)  
| convert ctime(recentTime) 
| sort -diff

read more here:

hope it helps

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...