<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to exclude Null Values from field extractions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306701#M57831</link>
    <description>&lt;P&gt;Oh, maybe @somesoni2 solution can be useful - &lt;A href="https://answers.splunk.com/answers/434015/is-it-possible-to-replace-null-fields-at-index-tim.html"&gt;Is it possible to replace null fields at index-time?&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 27 Aug 2017 01:38:19 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2017-08-27T01:38:19Z</dc:date>
    <item>
      <title>How to exclude Null Values from field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306698#M57828</link>
      <description>&lt;P&gt;I am building a TA. &lt;/P&gt;

&lt;P&gt;The issue I am having is the log file has a field error="". Even though it is null the error field is still there and causing CIM to tag the logs as error. I am hoping you can help me to only return the error field if there is a value other than null. Also note, I am looking for a way to do this without having to write a regex string as I have the same issue across a bunch of other sourcetypes.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;30&amp;gt;2017:08:27-10:30:12 sophos httpproxy[19742]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" srcip="1.1.1.1" dstip="1.1.1.1" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="855" request="0xdffdb" url="https://www.google.com.au/" referer="" error="" authtime="0" dnstime="579003" cattime="288" avscantime="0" fullreqtime="109809548" device="0" auth="0" ua="" exceptions="" category="145" reputation="trusted" categoryname="Search Engines" application="google" app-id="182"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 27 Aug 2017 01:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306698#M57828</guid>
      <dc:creator>dsofoulis</dc:creator>
      <dc:date>2017-08-27T01:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude Null Values from field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306699#M57829</link>
      <description>&lt;P&gt;Similar question at &lt;A href="https://answers.splunk.com/answers/216026/how-do-i-remove-a-null-field.html"&gt;How do I remove a null field?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Aug 2017 01:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306699#M57829</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-08-27T01:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude Null Values from field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306700#M57830</link>
      <description>&lt;P&gt;thanks for sharing, but will only remove the null value when performing a search. I need to this to happen at index time.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Aug 2017 01:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306700#M57830</guid>
      <dc:creator>dsofoulis</dc:creator>
      <dc:date>2017-08-27T01:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude Null Values from field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306701#M57831</link>
      <description>&lt;P&gt;Oh, maybe @somesoni2 solution can be useful - &lt;A href="https://answers.splunk.com/answers/434015/is-it-possible-to-replace-null-fields-at-index-tim.html"&gt;Is it possible to replace null fields at index-time?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Aug 2017 01:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306701#M57831</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-08-27T01:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude Null Values from field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306702#M57832</link>
      <description>&lt;P&gt;Did that solution work @dsofoulis? If so we can close the question.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 16:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306702#M57832</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-08-29T16:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude Null Values from field extractions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306703#M57833</link>
      <description>&lt;P&gt;You would probably be best to strip the null error completely out of the raw event with this on your Indexers:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SEDCMD_remove_empty_error_KVP = "s/\s+error=\"\"//"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Aug 2017 19:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-exclude-Null-Values-from-field-extractions/m-p/306703#M57833</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-29T19:18:27Z</dc:date>
    </item>
  </channel>
</rss>

