index="usb_weekly_data" |rex field="src_file_name" (?
above query returns me :
presentation 47
but if I change the keyword to "halla" then it is not matching in the "src_field_name" field, then it should give me 0 as an output like :
halla 0
Please help me to get this type of 0 output for non-matching keywords !!
Please help me this time, I have been searching for the solution , but didnt get yet !!
Your help would be highly appreciated !!
Thanks in Advance
This previous answer may help so that you can represent no results found as a 0:
http://splunk-base.splunk.com/answers/59589/no-results-found-to-be-represented-as-null-or-0
This previous answer may help so that you can represent no results found as a 0:
http://splunk-base.splunk.com/answers/59589/no-results-found-to-be-represented-as-null-or-0
Many Many thanks sdaniels for this , this really helped me a lot, I appreciate your help for this and hope to get same assistance in future also. Once again very very thanks 🙂