Splunk Search

How do you visualize 'zero' value in an area?

hyeongn
Engager

Hello, I'm a Korean beginner, Splunker

index=my sourcetype=my2 sernder_ip=my3

| table _time | stats count by _time | sort - _time


Here, even if the data is zero, I want to visualize the graph 

 

help me plz

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @hyeongn,

I asked to Splunk designers (using "Splunk Ideas") to add a feature to display zero instead of "no results" in panels and this idea is in evaluation, if you think that it could be a good idea, vote for it!

Anyway, in the meantime, you could use something like this:

index=my sourcetype=my2 sernder_ip=my3
| stats count by _time 
| append [ | makeresults | eval count=0 ]
| stats sum(count) AS count by _time  
| sort - _time

Ciao.

Giuseppe

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

An area chart will show zero if it is in the data - I suspect your issue is that if there are no events for a particular time, your don't have a zero count for that time. This is because you have used stats. Try timechart instead

index=my sourcetype=my2 sernder_ip=my3

| timechart count
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hyeongn,

I asked to Splunk designers (using "Splunk Ideas") to add a feature to display zero instead of "no results" in panels and this idea is in evaluation, if you think that it could be a good idea, vote for it!

Anyway, in the meantime, you could use something like this:

index=my sourcetype=my2 sernder_ip=my3
| stats count by _time 
| append [ | makeresults | eval count=0 ]
| stats sum(count) AS count by _time  
| sort - _time

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...