I have a data file , this source file does not contain any data on most days .. Its a valid scenario only . But since it does not have any data my panel in dashboards shows "" No results found"
index="xyz" source="*RatedUsg_OutSeq.dat" | eventstats max(Extract_Time) AS most_recent | where (Extract_Time = most_recent) | table Extract_Time File_Name File_Sequence Source_System_Key.
i am new to Splunk . My requirment is on those days where .dat file is empty it should dispaly a message "No Records Today" on other days that particular query should work.
Please help .I needed it to procced further .
The appendpipe command can do that.
index="xyz" source="*RatedUsg_OutSeq.dat"
| eventstats max(Extract_Time) AS most_recent
| where (Extract_Time = most_recent)
| appendpipe [ stats count | eval File_Name = "No Records Today" | where count = 0 | fields - count ]
| table Extract_Time File_Name File_Sequence Source_System_Key
The appendpipe command can do that.
index="xyz" source="*RatedUsg_OutSeq.dat"
| eventstats max(Extract_Time) AS most_recent
| where (Extract_Time = most_recent)
| appendpipe [ stats count | eval File_Name = "No Records Today" | where count = 0 | fields - count ]
| table Extract_Time File_Name File_Sequence Source_System_Key
Thank You so much . It helped