I have a column
Ex Values (Suppose the search has 4 events here):
Now my intention is I want
_time to increment by one second, that even though there is not row with 2017-08-11 12:06:52, I want to add a row with all other columns to be 0,
So my new data should look like
So all the appended time which was not there should have the other column entries of search as 0. The new search should have 8 events now.
Can someone please help me with this, as I am not able to understand how to do it.
Hey @patilsh, This might help? https://answers.splunk.com/answers/10147/how-to-show-events-per-second-in-timechart-regardless-of-sp... I'm just a community moderator, so I'll keep an eye on the post and try new tags if no experts see it this weekend.
You don't explain exactly what your search is, but you can probably get most of what you need to use by reading the following answers entry:
And here is the