Can you illustrate how you obtain incomingcount rejectedcount invalidcount topcount trmpcount topiccount? As a habit, always share how data looks like. If you just count stuff, there should be no "...
See more...
Can you illustrate how you obtain incomingcount rejectedcount invalidcount topcount trmpcount topiccount? As a habit, always share how data looks like. If you just count stuff, there should be no "empty" column. (Also, are you asking about empty row or empty column?) For example, if you have this data set Application incoming invalid rejected top trmp top Login come something some other Login some more some stuff Login stuff stuff Success come in more stuff and you use this to produce those count columns | stats count(incoming) as incomingcount count(rejected) as rejectedcount count(invalid) as invalidcount count(top) as topcount count(trmp) as trmpcount count(topic) as topiccount by Application Splunk should give you Application incomingcount rejectedcount invalidcount topcount trmpcount topiccount Login 1 0 2 3 0 0 Success 1 0 0 1 0 0 Here is my data emulation to produce that mock input. | makeresults format=csv data="Application, incoming, rejected, invalid, top, trmp, topic
Login, come, , something, some other
Login, , , some more, some stuff
Login, , , , stuff stuff
Success, come in, , , more stuff"