Splunk Search

Dots/gaps in timechart when using sum(packets) by destination

Path Finder

When I use "(base search) | timechart sum(packets) by destination useother=f usenull=f", I get gaps in my timechart:

alt text

When I use a longer time frame of 1 day, I also get gaps:
alt text

In another timechart, I have the exact same base search and just "| timechart sum(packets)", and it has no gaps. I found that when I add "by destination" to this one, it also gets the gaps/dots.
As far as I can see on https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchReference/Timechart timechart should convert null values to 0 by default...
Any ideas?

0 Karma
1 Solution

SplunkTrust
SplunkTrust

under visualization -> click format -> general tab -> click on connect in "Null Value" line

see attached screenshot
alt text

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

under visualization -> click format -> general tab -> click on connect in "Null Value" line

see attached screenshot
alt text

View solution in original post

0 Karma

Path Finder

Thank you for that simple solution. I found the second option called "Zero" looked nicer though!

0 Karma