Splunk Search

How can I resolve return 0 for "No Results Found"?

philh
Explorer

Hi, I have a query where I'm extrapolating type based on a conditional then counting by type. This works great when there are events for both cases, but I'd also like to show a value of 0 for a given type when there aren't any events for that type. I've seen some other posts using fillnull and appendpipe but those examples haven't worked for my use case. Any help would be appreciated!

 

| eval type=if(user_action="place_order", "AddInOrdersPlaced", "AddInForwardedOrders")
| convert timeformat="%Y-%m-%d" ctime(_time) AS date
| chart count over date by type

 

 

Labels (4)
0 Karma
1 Solution

diogofgm
SplunkTrust
SplunkTrust

If you're looking into a time range, and you're using chart over date, the chart won't create the missing dates where both types do not have an event. 
What you can try to do instead is using a timechart that for the given time range with create the missing dates of the span you select.

| eval type=if(user_action="place_order", "AddInOrdersPlaced", "AddInForwardedOrders")
| timechart span=1d count by type
| fillnull value="0" AddInOrdersPlaced AddInForwardedOrders


 

------------
Hope I was able to help you. If so, some karma would be appreciated.

View solution in original post

diogofgm
SplunkTrust
SplunkTrust

If you're looking into a time range, and you're using chart over date, the chart won't create the missing dates where both types do not have an event. 
What you can try to do instead is using a timechart that for the given time range with create the missing dates of the span you select.

| eval type=if(user_action="place_order", "AddInOrdersPlaced", "AddInForwardedOrders")
| timechart span=1d count by type
| fillnull value="0" AddInOrdersPlaced AddInForwardedOrders


 

------------
Hope I was able to help you. If so, some karma would be appreciated.

philh
Explorer

@diogofgm This works great thank you!

0 Karma

PickleRick
Ultra Champion

You can't find something that isn't there. See https://www.duanewaddle.com/proving-a-negative/ for ideas

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...