Splunk Search

show fields with no values in a timechart

Builder

Hello Expert,

I'm showing a multilines graph using this search:

sourcetype="mysource" thefield="x" or thefield="y" or thefield="z" | timechart span=1d count by thefield

The graph is showing 2 lines one for x and one for y because there are no values that is equal to "z".

I need to show 3 lines x,y,z on the graph and consider z as zero.
How to do that?

Tags (1)
0 Karma
1 Solution

Builder

Try usenull and useother

sourcetype="mysource" thefield="x" or thefield="y" or thefield="z" | timechart span=1d count by thefield usenull=f useother=f

View solution in original post

0 Karma

Builder

Try usenull and useother

sourcetype="mysource" thefield="x" or thefield="y" or thefield="z" | timechart span=1d count by thefield usenull=f useother=f

View solution in original post

0 Karma

Communicator

Is this really working? It didn't work for me.

0 Karma