Splunk Search

Timechart filldown

perrinj2
Path Finder

 

I have a dashboard search which ends with a timechart like this

 

| eval VUser=if(isnotnull(Stop_time),0,VUser)

| timechart count(VUser) by Protocol

 

The event with the VUser field is only present for one time interval of the timechart series so I want do the equivalent of a filldown until Stop_time is not null and then reset the VUser count.

Filldown only works when there are nulls. In the above example when there are no values for VUser timechart generates a zero value rather than a null which is why filldown is no good.

 

What else can I do in this case?

 

 

Labels (1)
0 Karma

perrinj2
Path Finder

Good idea but this only works if I remove the "by Protocol" split which I need

The stats tab shows a series of columns with Protocol values as headings. How can I refer to these fields to try the eval command to change zero to null?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try "fudging" it by setting the zero values to nulls so filldown works.

| eval VUser=if(isnotnull(Stop_time),0,VUser)
| timechart count(VUser) as Count by Protocol
| eval Count=if(Count==0, NULL, Count)
| filldown Count

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...