Hello All,
Assuming the following timechart
| timechart count span=1mon
If there are no results for the current month splunk will omit it completely. This means that if I run the command today (February 5th, 2019), I will have:
_time,count
2018-11,43
2018-12,23
2019-01,65
Instead, what I'd like to have is:
_time,count
2018-11,43
2018-12,23
2019-01,65
2019-02,0
How can I achieve this?
Thank you and best regards,
Andrew
Try adding a makecontinuous _time span=1mon
- this should give you the desired result.