Splunk Search

Dots/gaps in timechart when using sum(packets) by destination

splunklearner12
Path Finder

When I use "(base search) | timechart sum(packets) by destination useother=f usenull=f", I get gaps in my timechart:

alt text

When I use a longer time frame of 1 day, I also get gaps:
alt text

In another timechart, I have the exact same base search and just "| timechart sum(packets)", and it has no gaps. I found that when I add "by destination" to this one, it also gets the gaps/dots.
As far as I can see on https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchReference/Timechart timechart should convert null values to 0 by default...
Any ideas?

0 Karma
1 Solution

adonio
Ultra Champion

under visualization -> click format -> general tab -> click on connect in "Null Value" line

see attached screenshot
alt text

View solution in original post

0 Karma

adonio
Ultra Champion

under visualization -> click format -> general tab -> click on connect in "Null Value" line

see attached screenshot
alt text

0 Karma

splunklearner12
Path Finder

Thank you for that simple solution. I found the second option called "Zero" looked nicer though!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...