In my dashboard, I have "Alerts Open" timechart single value panels with colour ranges that are using the following searches:
index="<client>" case_id | dedup 1 case_id sortby -_time | search (status=new OR status=under_investigation) | timechart sum(alert_count) as alert_count_total | addcoltotals
This works fine in all aspects when there are actually alerts open.
However, I found that when no alerts are open then it simply displays "No results found" but I wanted it to stay on 0. I tried using "if(isnull" and "fillnull" neither of which worked but I found that using the following search resolves this:
index="<client>" case_id | dedup 1 case_id sortby -_time | search (status=new OR status=under_investigation) | timechart sum(alert_count) as alert_count_total | append [| stats count as alert_count] | addcoltotals
However, a side of that is that the panels are now using the colours for the max ranges, even though the value is 0 and the max ranges are, for example, "from 100 to max". This can be seen below.
For some reason, it seems that it's the timechart that's causing this because removing it uses the correct colours. This can be seen below.
I found:
I found: