Splunk Search

Displaying a blank timechart in a dashboard panel when no results found.

jason_hotchkiss
Communicator

I am working with a time chart panel in a dashboard.  This dashboard will have a filter for "hosts".  However, this particular sourcetype has a small subset of the servers included in the filter.  I would like this panel to display a blank chart if the filtered server is not part of the values for the dashboards other values.  This is what I have written so far:

<base search>
| search host IN ($host$)
| timechart max(users) by host usenull=f useother=f limit=6
| addtotals
| table _time, host
| fillnull host

What happens here is that only the blank time chart (even when the correct server is selected).

Labels (3)
0 Karma
1 Solution

jason_hotchkiss
Communicator

I found my answer in this thread: https://community.splunk.com/t5/Splunk-Search/Timecharts-and-how-to-avoid-quot-no-results-found-insp...

<base search>
| search host IN ($host$)
| timechart max(users) by host usenull=f useother=f limit=6
| addtotals
| table _time, host
| fillnull host
| appendpipe
[stats count
| eval NoResult=""
| where count=0
| fields - count]

View solution in original post

0 Karma

jason_hotchkiss
Communicator

I found my answer in this thread: https://community.splunk.com/t5/Splunk-Search/Timecharts-and-how-to-avoid-quot-no-results-found-insp...

<base search>
| search host IN ($host$)
| timechart max(users) by host usenull=f useother=f limit=6
| addtotals
| table _time, host
| fillnull host
| appendpipe
[stats count
| eval NoResult=""
| where count=0
| fields - count]

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...