Splunk Search

Splunk display 0 when no results found from last x minutes

sahil237888
Path Finder

Hi Team,

Need help in creating a query.
I want to display 0 when no data/events found. But I am getting "No results found. Try expanding the time range."
either by using "fillnull value =0" or "eval Data=if(isnull(Data),0,Data)". but no result.

I am using query as :

sourcetype=systems earliest=-15m
| timechart span=1m count as Data
| eval Data=if(isnull(Data),0,Data)

OR

sourcetype=systems earliest=-15m
| timechart span=1m count as Data
| fillnull value=0 Data

Tags (1)
0 Karma

niketn
Legend

@sahil237888 try one of my older answers you can use $job.resultCount$ inside search event handler for above query and if the count is 0 unset the token to show a different panel with 0 count using rejects otherwise display the time chart. The answer in discussion also talks about showing empty timechart for 0 result count if required.

https://answers.splunk.com/answers/595248/timechart-with-no-data-gives-no-results-found.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

sahil237888
Path Finder

Hi @niketnilay,

Actually the thing is I am creating an alert so $job.resultcount$ can work only with dashboards but not with query.
Any suggestion on that.

0 Karma

niketn
Legend

That is the second option I mentioned which is explained in the message of my answer above.
Have you tried adding the following appendpipe to your existing search?

sourcetype=systems earliest=-15m
| timechart span=1m count as Data 
| fillnull value=0 Data
| appendpipe 
    [| makeresults 
    | bin _time span=1m] 
| dedup _time
| fillnull value=0 Data

Following is a run anywhere example based on the answer posted in the above answer:

index=_internal sourcetype=splunkd log_level=ERROR 
| timechart span=1m count as Data
| appendpipe 
    [| makeresults 
     | bin _time span=1m] 
| dedup _time
| fillnull value=0 Data
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...