Need help in getting the value in vizualization as 0 instead of no result.
index=nw_syslog "FPC"
|rex field=_raw "FPC: (?.*), jnxFruTyp"
| stats latest(_time) as Time_CST count by hostname,MEMBER
| sort - Time_CST
| fieldformat Time_CST=strftime(Time_CST,"%x %X")
| head 20
| stats sum(count)
Visualization used 42 single value.
Hello:
You can find a solution in this link:
https://answers.splunk.com/answers/582253/replacing-no-results-found-with-0.html
| appendpipe [stats count | where count=0]
Hello:
You can find a solution in this link:
https://answers.splunk.com/answers/582253/replacing-no-results-found-with-0.html
| appendpipe [stats count | where count=0]
@jerinvarghese
Try by appending | appendcols [stats count ]
like..
Your Search | stats sum(count) as count | appendcols [stats count ]
Note: I have updated stats command,
that worked, thanks so much for that help.
Great @jerinvarghese. Can you please upvote and accept this answer to close this question?