Splunk Search

Timechart to filter inactive buckets

Communicator

I need help with time chat query. Basically I want to display all the graph occurrences where the count hit 0 and stayed like that.

base search | timechart count by URL limit=100

That's where I am and there are some URL hits which were active at certain time then count was 0. I am searching through more than 1 URL and only want those whose count was zero after specific time.
alt text

0 Karma

SplunkTrust
SplunkTrust

Hi @muralianup,

Try this

base search | timechart count by URL limit=100|untable _time URL count|where (count = 0 AND _time<your_time_filter)
0 Karma

SplunkTrust
SplunkTrust

Hi @muralianup,

Did this work for you?

0 Karma