Splunk Search
Highlighted

How to display bucket/histogram data with zero count?

Path Finder

I'm trying to run a bucket/histogram of data but I want to display buckets that have zero count. By default, bucket seems to hide those entries.

Quick example -- histogram of CPU-load on a group of machines. Each machine logs cpu-load as 'x' every 15min, I pick the latest entry for each host and bucket that data:

(search command) |stats first(x) as ff by host |bucket ff bins=10 start=0 end=10 |chart count(ff) over ff

Is there a way to tell bucket (or chart) that it should display all bins, even if they are zero-count?

Tags (1)
Highlighted

Re: How to display bucket/histogram data with zero count?

Splunk Employee
Splunk Employee

You should probably just not invoke bucket at all, and just use chart count(ff) over ff bins=10, or use makecontinuous instead of bucket.

View solution in original post

Highlighted

Re: How to display bucket/histogram data with zero count?

Path Finder

That works exactly how I wanted it -- thanks!

0 Karma
Highlighted

Re: How to display bucket/histogram data with zero count?

Builder

Thanks for making me aware of the makecontinuous command

0 Karma