Dashboards & Visualizations

how to display value for a filed if it has no value?

AzmathShaik
Path Finder

Hello All,

i have a dashboard where in drop down am displaying values for user index=user_stats | stats count by user. i have a problem where some log events has user value as below user = (user has no value) so in drop down, instead of blank space i want to display as some value say null or no_user so user can select that value to see all results which has blank value for user attribute
can any one help me in it

My drop down query:

index=user_stats sourctype=user_accounts | stats count by user

My panel query

index=user_stats sourctype=user_accounts $user$

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Try this index=user_stats sourcetype=user_accounts | eval user=if(isnull(user),"No_user", user) | stats count by user for your populating search
Then in your panel search, try index=user_stats sourcetype=user_accounts | eval SrchUser = if( $user$="No_user", undefField, $user$) | search user=SrchUser
Make sure "undefField" is a fieldname that you know won't exist; that should result in searching for a null user if No_user was selected

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi AzmathShaik,
did you tried with fillnull command?
Bye.
Giuseppe

0 Karma

AzmathShaik
Path Finder

yeah i tried as below

index=user_stats sourctype=user_accounts | fillnull value=no_user user |stats count by user
but no luck

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...