Splunk Search

Displaying a blank timechart in a dashboard panel when no results found.

jason_hotchkiss
Communicator

I am working with a time chart panel in a dashboard.  This dashboard will have a filter for "hosts".  However, this particular sourcetype has a small subset of the servers included in the filter.  I would like this panel to display a blank chart if the filtered server is not part of the values for the dashboards other values.  This is what I have written so far:

<base search>
| search host IN ($host$)
| timechart max(users) by host usenull=f useother=f limit=6
| addtotals
| table _time, host
| fillnull host

What happens here is that only the blank time chart (even when the correct server is selected).

Labels (3)
0 Karma
1 Solution

jason_hotchkiss
Communicator

I found my answer in this thread: https://community.splunk.com/t5/Splunk-Search/Timecharts-and-how-to-avoid-quot-no-results-found-insp...

<base search>
| search host IN ($host$)
| timechart max(users) by host usenull=f useother=f limit=6
| addtotals
| table _time, host
| fillnull host
| appendpipe
[stats count
| eval NoResult=""
| where count=0
| fields - count]

View solution in original post

0 Karma

jason_hotchkiss
Communicator

I found my answer in this thread: https://community.splunk.com/t5/Splunk-Search/Timecharts-and-how-to-avoid-quot-no-results-found-insp...

<base search>
| search host IN ($host$)
| timechart max(users) by host usenull=f useother=f limit=6
| addtotals
| table _time, host
| fillnull host
| appendpipe
[stats count
| eval NoResult=""
| where count=0
| fields - count]

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...