Splunk Search

How to return Zero if there is nothing returned for today?

ashidhingra
Path Finder

index=abc
| stats latest(_time) AS Last_time by day
| convert ctime(Last_time)
| sort by Last_time desc
 

for example, 

Monday 06/13/2022 13:03:11
Tuesday 06/13/2022 13:03:11
Wednesday 06/13/2022 13:03:11
Thursday 06/13/2022 13:03:11
Friday 06/12/2022 13:03:11
Saturday 06/13/2022 13:03:11
Sunday 06/13/2022 13:03:11

 

I want the search to return 0 // or something else if there was no event today.

Monday 06/13/2022 13:03:11
Tuesday 06/13/2022 13:03:11
Wednesday 06/13/2022 13:03:11
Thursday 06/13/2022 13:03:11
Friday 0 // or something else
Saturday 06/13/2022 13:03:11
Sunday 06/13/2022 13:03:11

 

Is that possible. 

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

timechart will fill in the blanks in the time line - try something like this

| timechart latest(_time) as latest_time
| fillnull value=0
0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...