Splunk Search

How to return Zero if there is nothing returned for today?

ashidhingra
Path Finder

index=abc
| stats latest(_time) AS Last_time by day
| convert ctime(Last_time)
| sort by Last_time desc
 

for example, 

Monday 06/13/2022 13:03:11
Tuesday 06/13/2022 13:03:11
Wednesday 06/13/2022 13:03:11
Thursday 06/13/2022 13:03:11
Friday 06/12/2022 13:03:11
Saturday 06/13/2022 13:03:11
Sunday 06/13/2022 13:03:11

 

I want the search to return 0 // or something else if there was no event today.

Monday 06/13/2022 13:03:11
Tuesday 06/13/2022 13:03:11
Wednesday 06/13/2022 13:03:11
Thursday 06/13/2022 13:03:11
Friday 0 // or something else
Saturday 06/13/2022 13:03:11
Sunday 06/13/2022 13:03:11

 

Is that possible. 

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

timechart will fill in the blanks in the time line - try something like this

| timechart latest(_time) as latest_time
| fillnull value=0
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...