Splunk Search

How do you visualize 'zero' value in an area?

hyeongn
Engager

Hello, I'm a Korean beginner, Splunker

index=my sourcetype=my2 sernder_ip=my3

| table _time | stats count by _time | sort - _time


Here, even if the data is zero, I want to visualize the graph 

 

help me plz

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @hyeongn,

I asked to Splunk designers (using "Splunk Ideas") to add a feature to display zero instead of "no results" in panels and this idea is in evaluation, if you think that it could be a good idea, vote for it!

Anyway, in the meantime, you could use something like this:

index=my sourcetype=my2 sernder_ip=my3
| stats count by _time 
| append [ | makeresults | eval count=0 ]
| stats sum(count) AS count by _time  
| sort - _time

Ciao.

Giuseppe

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

An area chart will show zero if it is in the data - I suspect your issue is that if there are no events for a particular time, your don't have a zero count for that time. This is because you have used stats. Try timechart instead

index=my sourcetype=my2 sernder_ip=my3

| timechart count
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hyeongn,

I asked to Splunk designers (using "Splunk Ideas") to add a feature to display zero instead of "no results" in panels and this idea is in evaluation, if you think that it could be a good idea, vote for it!

Anyway, in the meantime, you could use something like this:

index=my sourcetype=my2 sernder_ip=my3
| stats count by _time 
| append [ | makeresults | eval count=0 ]
| stats sum(count) AS count by _time  
| sort - _time

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...