Splunk Search

How to get a timechart to display data for the entire selected time range including 0 data points?

sugitime
Explorer

I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on January 25th or 26th and that the data begin to be present on Jan 27th, but I want the 0 data points to illustrate the absence of traffic.

Every time I perform the search, I only get data from the 27th onward.

Is there a way to force Splunk to show me times when there is even 0 data to show, just to illustrate the point that no data is present?

Tags (2)

dolivasoh
Contributor

fillnull value=0 {{field_name}} | timechart....

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...