Splunk Search

How to get a timechart to display data for the entire selected time range including 0 data points?

sugitime
Explorer

I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on January 25th or 26th and that the data begin to be present on Jan 27th, but I want the 0 data points to illustrate the absence of traffic.

Every time I perform the search, I only get data from the 27th onward.

Is there a way to force Splunk to show me times when there is even 0 data to show, just to illustrate the point that no data is present?

Tags (2)

dolivasoh
Contributor

fillnull value=0 {{field_name}} | timechart....

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...