Splunk Search

Fill missing values from stats command

aohls
Contributor

I am using a bin of 10 minutes with stats for the past hour. What I am running into is that when doing so not all items in my stats command have a count for one of the buckets. For example one might show up for the 10, 20, 40 minute buckets but, I want to the 30 and 50 minute buckets to show blank values. What is the best way to accomplish this? Fillnull does not work for this since there is no null value, the value just is not showing at all.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Depending on what statistics you producing, you may be able to replace stats with timechart, which automatically fills in missing time periods.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...