When I use
"(base search) | timechart sum(packets) by destination useother=f usenull=f", I get gaps in my timechart:
When I use a longer time frame of 1 day, I also get gaps:
In another timechart, I have the exact same base search and just
"| timechart sum(packets)", and it has no gaps. I found that when I add "by destination" to this one, it also gets the gaps/dots.
As far as I can see on https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchReference/Timechart timechart should convert null values to 0 by default...