I'm trying to display a timechart based on count by a type.
But, for a certain type, the value will always be 0 for a certain time.
is it possible to tell Splunk to simply stop displaying the line from a certain datetime ? or when the count is 0 ?
The screenshot below shows the different lines and the part I marked is supposed to be hidden.
How about adding , where count>0
in your query
that doesn't work for me. When I enter where count>0 nothing appends. Not sure if this where clause is being taken in account.