When I use "(base search) | timechart sum(packets) by destination useother=f usenull=f", I get gaps in my timechart:
"(base search) | timechart sum(packets) by destination useother=f usenull=f"
When I use a longer time frame of 1 day, I also get gaps:
In another timechart, I have the exact same base search and just "| timechart sum(packets)", and it has no gaps. I found that when I add "by destination" to this one, it also gets the gaps/dots.
As far as I can see on https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchReference/Timechart timechart should convert null values to 0 by default...
"| timechart sum(packets)"
under visualization -> click format -> general tab -> click on connect in "Null Value" line
see attached screenshot
View solution in original post
Thank you for that simple solution. I found the second option called "Zero" looked nicer though!