Splunk Search

How to make Search Visualization where count=0?

ToddClayton
Engager

Complete novice here, but I was able to get my search result thanks to others who have had questions.

Currently I'm successfully running a search that shows me by hour where count = 0

 

<<search>>

| timechart span=1h count

| where count=0

 

I get my date/hour in statistics showing me each hour that's getting a count of 0. 

But I'd like to visualize it better. Hit Visualize and it shows me a nice chart with a flatlined Y axis. Of course, because everything is 0.

I can't quite wrap my head around showing this data in a more visually appealing format. Every day there are a couple of "0 count" hours. Maybe something that shows each day and the number of "0 count" hours? 

Thanks in advance.

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try adding | timechart span=1d count to the end of the query.  That should give the number of hours with zero counts each day.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Try adding | timechart span=1d count to the end of the query.  That should give the number of hours with zero counts each day.

---
If this reply helps you, Karma would be appreciated.

ToddClayton
Engager

That helps greatly!

Thank you very much @richgalloway!

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...