Hi @splunkuser320 ,
as @ITWhisperer said, if you could share your code, it's easier to help you, anyway, supposing your code, you could use something like this:
<your_search>
| timechart count BY host
| eval
failed=if(isnull(failed),0,failed),
success=if(isnull(success),0,success)
Ciao.
Giuseppe
Hi @splunkuser320 ,
as @ITWhisperer said, if you could share your code, it's easier to help you, anyway, supposing your code, you could use something like this:
<your_search>
| timechart count BY host
| eval
failed=if(isnull(failed),0,failed),
success=if(isnull(success),0,success)
Ciao.
Giuseppe
Please share your current SPL, preferably in a code block </>