Splunk Search

How can I show all x-axis labels , even result is zero with timechart command

nagarjuna280
Communicator

I want data for the last ten months, but few months doesn't have data,I am using
| timechart span=1mon count
then I am not able to see labels (months) with empty spaces. showing only, labels which has data.

I want all labels(months) event result is zero

Tags (2)
0 Karma
1 Solution

woodcock
Esteemed Legend

This makes no sense, filling in blank spots is fundamental to what timechart does. Take a look at this run-anywhere example that proves that it fills in gaps where there is no data:

index=_* date_minute>20 | timechart span=1m count

View solution in original post

woodcock
Esteemed Legend

This makes no sense, filling in blank spots is fundamental to what timechart does. Take a look at this run-anywhere example that proves that it fills in gaps where there is no data:

index=_* date_minute>20 | timechart span=1m count
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...