Splunk Search

How do you visualize 'zero' value in an area?

hyeongn
Engager

Hello, I'm a Korean beginner, Splunker

index=my sourcetype=my2 sernder_ip=my3

| table _time | stats count by _time | sort - _time


Here, even if the data is zero, I want to visualize the graph 

 

help me plz

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @hyeongn,

I asked to Splunk designers (using "Splunk Ideas") to add a feature to display zero instead of "no results" in panels and this idea is in evaluation, if you think that it could be a good idea, vote for it!

Anyway, in the meantime, you could use something like this:

index=my sourcetype=my2 sernder_ip=my3
| stats count by _time 
| append [ | makeresults | eval count=0 ]
| stats sum(count) AS count by _time  
| sort - _time

Ciao.

Giuseppe

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

An area chart will show zero if it is in the data - I suspect your issue is that if there are no events for a particular time, your don't have a zero count for that time. This is because you have used stats. Try timechart instead

index=my sourcetype=my2 sernder_ip=my3

| timechart count
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hyeongn,

I asked to Splunk designers (using "Splunk Ideas") to add a feature to display zero instead of "no results" in panels and this idea is in evaluation, if you think that it could be a good idea, vote for it!

Anyway, in the meantime, you could use something like this:

index=my sourcetype=my2 sernder_ip=my3
| stats count by _time 
| append [ | makeresults | eval count=0 ]
| stats sum(count) AS count by _time  
| sort - _time

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...