Hi,
How to get a single value visualization to display "0" instead of "N/A" in splunk dashboard when there is no matching event?
index=main source="blr-trend" | stats count values(COMP_NAME) AS Computer_NAME,values(DOMAIN) AS Domain, values(MAC) AS MAC, values(ROOTKIT) AS RootKit, values(LOGON_USER) AS Logon_User by ENGINE |reverse| streamstats current=t count AS SERIAL | where SERIAL > 1 |reverse| fields - SERIAL | stats sum(count) AS total
For this query i m getting N/A, but need 0 is results are N/A
Thanks,
Vijay
... View more