Splunk Search

Fill missing values from stats command

aohls
Contributor

I am using a bin of 10 minutes with stats for the past hour. What I am running into is that when doing so not all items in my stats command have a count for one of the buckets. For example one might show up for the 10, 20, 40 minute buckets but, I want to the 30 and 50 minute buckets to show blank values. What is the best way to accomplish this? Fillnull does not work for this since there is no null value, the value just is not showing at all.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Depending on what statistics you producing, you may be able to replace stats with timechart, which automatically fills in missing time periods.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...