Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to get my transaction search to return "0" instead of "no results found" if no events are found?

$
0
0
I am trying to use the transaction command to get duration between two events In case there are no such events, I would like the search to return 0 instead of "no results found". This following command isn't working: index=main host="xyz" | transaction startswith="keyword1" endswith="keyword2" | eval spent_time = duration | stats sum(spent_time) as total_spent_time | table total_spent_time | fillnull value=NULL

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>