Hi,
I am doing a prediction with a "timechart count" as base search, which works fine:
index=logins username | timechart span=1d count | predict count
But when the base search has leading "zero event count" days, timechart cuts off these days. This happens whether fillnull is used or not. This now causes a problem with predict, as predict requires a minimum of two data points: Predict gives its first results for the third day, but it should also report the change on day one and two.
Is there a way to make timechart keep the empty leading results?
Thanks,
Oliver
Use fillnull (from http://answers.splunk.com/answers/106774😞
index=logins username | fillnull value=NoValue | timechart span=1d count | predict count
Use fillnull (from http://answers.splunk.com/answers/106774😞
index=logins username | fillnull value=NoValue | timechart span=1d count | predict count
This works, thank you - I thought I had tried it 🙂
I found this, but isn't there an easier solution? The Splunk GUI also displays the right results just before they get chopped off in the page refresh an instant later 😉
http://answers.splunk.com/answers/118496/fill-in-0-for-timechart-with-missing-values