Hello,
I have the following query:
sourcetype=access_* action="purchase"
| timechart count by productName usenull=f useother=f
And I get a timechart with zeros: https://imgur.com/a/XWdbIZH
Do you know a way to remove that rows with zeros? Is it possible to reference timechart "count" as a variable to use it with "where" command: | where $count$ > 0
, or something like that?
Thanks in advance
@jam00 you should try timechart option cont=f
, the rows with all zeros will be removed.
sourcetype=access_* action="purchase"
| timechart count by productName cont=f usenull=f useother=f
Refer to documentation: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timechart#Optional_arguments
@jam00 you should try timechart option cont=f
, the rows with all zeros will be removed.
sourcetype=access_* action="purchase"
| timechart count by productName cont=f usenull=f useother=f
Refer to documentation: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timechart#Optional_arguments
@niketnilay I hadn't considered that argument. Thank you so much.