http://answers.splunk.com/answers/62196/any-way-to-return-zero-result-count-stats-of-a-field-such-as-the-host-or-sourcteype-field/62594
and
http://answers.splunk.com/answers/6646/search-events-against-a-lookup-table-and-show-matching-count/6649
address similar problems.
... View more
Try this
search.. |rangemap field=waitTimeSec "1-60"=0-60 "61-600"=61-600 "601-6000000"=601-6000000, "6000001-1600000"=6000001-1600000 | stats count(eval(range="1-60")) as "1-60" count(eval(range="61-600")) as "61-600" count(eval(range="601-6000000")) as "601-6000000" count(eval(range="6000001-1600000")) as "6000001-1600000" by appName | untable appName buck count
... View more