Splunk Enterprise

help to display 0 & unit if there is no results

jip31
Motivator

hi

if tere is no results retourned I need to display 0 in my single panel and the unit whic is "sec"

So I need to display "0 sec" and the formatting options even if there is no results

how to do this please?

<single>
        <title>Bur</title>
        <search base="hang">
          <query>| stats perc90(hang_duration_sec) as hang_duration_sec </query>
        </search>
        <option name="drilldown">none</option>
        <option name="height">85</option>
        <option name="numberPrecision">0.0</option>
        <option name="rangeColors">["0x53a051","0xf8be34","0xf1813f","0xdc4e41"]</option>
        <option name="rangeValues">[0,5,10]</option>
        <option name="refresh.display">progressbar</option>
        <option name="unit">sec</option>
        <option name="useColors">1</option>
      </single>
Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| stats perc90(hang_duration_sec) as hang_duration_sec
| appendpipe [stats count as _events | where _events = 0 | eval hang_duration_sec = 0 ]

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats perc90(hang_duration_sec) as hang_duration_sec
| appendpipe [stats count as _events | where _events = 0 | eval hang_duration_sec = 0 ]
0 Karma

jip31
Motivator

thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...