<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to replace any multi values found in search result with true and if the value is null replace with No in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430799#M123146</link>
    <description>&lt;P&gt;Hi there!&lt;BR /&gt;
I am updating my question:&lt;BR /&gt;
Below is the scenario where I wanted to see what are the servers got patched since last 3 months. My query pulls up the below table showing server name and patches installed by month and if there is not patched installed for that specific month i did a fill null values to show as "Not Patched".  By doing this we just wanted to check if the server is patched for that month or not, we don't need the patch names to be shown.So I wanted to replace all those patch names to some other values like  "True"/Patched/yes. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7458iFCD6679173665D07/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2019 15:38:22 GMT</pubDate>
    <dc:creator>vinaykataaig</dc:creator>
    <dc:date>2019-08-07T15:38:22Z</dc:date>
    <item>
      <title>How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430799#M123146</link>
      <description>&lt;P&gt;Hi there!&lt;BR /&gt;
I am updating my question:&lt;BR /&gt;
Below is the scenario where I wanted to see what are the servers got patched since last 3 months. My query pulls up the below table showing server name and patches installed by month and if there is not patched installed for that specific month i did a fill null values to show as "Not Patched".  By doing this we just wanted to check if the server is patched for that month or not, we don't need the patch names to be shown.So I wanted to replace all those patch names to some other values like  "True"/Patched/yes. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7458iFCD6679173665D07/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 15:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430799#M123146</guid>
      <dc:creator>vinaykataaig</dc:creator>
      <dc:date>2019-08-07T15:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430800#M123147</link>
      <description>&lt;P&gt;What is your query?  What exactly do you want replaced with "True/Yes"?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 16:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430800#M123147</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-07T16:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430801#M123148</link>
      <description>&lt;P&gt;Thanks for the response, I have updated my question. &lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 18:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430801#M123148</guid>
      <dc:creator>vinaykataaig</dc:creator>
      <dc:date>2019-08-07T18:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430802#M123149</link>
      <description>&lt;P&gt;I have updated my answer pls try if it doesn't work then could you provide the splunk query to get this result?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 19:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430802#M123149</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2019-08-07T19:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430803#M123150</link>
      <description>&lt;P&gt;Please share your query.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 19:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430803#M123150</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-07T19:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430804#M123151</link>
      <description>&lt;P&gt;index="oswin" sourcetype="windowsupdatelog" |search "&lt;EM&gt;Patch Deployment&lt;/EM&gt;" AND "&lt;EM&gt;AGENT_INSTALLING_SUCCEEDED&lt;/EM&gt;"&lt;BR /&gt;&lt;BR /&gt;
| rex field=_raw "^(?:[^:\n]*:){9}\s+(?P.+)" &lt;BR /&gt;
| eval server = Upper(mvindex(split(host,"."),-0))&lt;BR /&gt;
| eval start=strptime(Time, "%Y-%m-%d %H:%M:%S.%N") &lt;BR /&gt;
| eval day = strftime(start, "%a") &lt;BR /&gt;
| eval Month = Upper(date_month) &lt;BR /&gt;
| chart values(ApplicablePatch) as ApplicablePatch by server Month | fillnull value="Not Patched" &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430804#M123151</guid>
      <dc:creator>vinaykataaig</dc:creator>
      <dc:date>2020-09-30T01:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430805#M123152</link>
      <description>&lt;P&gt;Try this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="oswin" sourcetype="windowsupdatelog" "Patch Deployment" AND "AGENT_INSTALLING_SUCCEEDED" 
| rex field=_raw "^(?:[^:\n]*:){9}\s+(?P.+)" 
| eval server = Upper(mvindex(split(host,"."),-0)) 
| eval start=strptime(Time, "%Y-%m-%d %H:%M:%S.%N") 
| eval day = strftime(start, "%a") 
| eval Month = Upper(date_month) 
| replace * WITH "Patched" IN ApplicablePatch 
| chart values(ApplicablePatch) as ApplicablePatch by server Month 
| fillnull value="Not Patched"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="oswin" sourcetype="windowsupdatelog" "Patch Deployment" AND "AGENT_INSTALLING_SUCCEEDED" 
| rex field=_raw "^(?:[^:\n]*:){9}\s+(?P.+)" 
| eval server = Upper(mvindex(split(host,"."),-0)) 
| eval start=strptime(Time, "%Y-%m-%d %H:%M:%S.%N") 
| eval day = strftime(start, "%a") 
| eval Month = Upper(date_month) 
| chart values(ApplicablePatch) as ApplicablePatch by server Month 
| fillnull value="Not Patched" 
| foreach JANUARY FEBRUARY MARCH APRIL MAY JUNE JULY AUGUST SEPTEMBER OCTOBER NOVEMBER DECEMBER 
    [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;=if(&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;="Not Patched","Not Patched","Patched")]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Aug 2019 20:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430805#M123152</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2019-08-07T20:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to replace any multi values found in search result with true and if the value is null replace with No</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430806#M123153</link>
      <description>&lt;P&gt;Actually First search worked for me. Thank you!! &lt;BR /&gt;
And also i thought of doing it another way as well, Just by  writing eval logic if the count(Applicable Patch) &amp;gt;"0" then show Patched if the value is null then Not patched. &lt;/P&gt;

&lt;P&gt;| replace * WITH "Patched" IN ApplicablePatch &lt;BR /&gt;
 | chart values(ApplicablePatch) as ApplicablePatch by server Month &lt;BR /&gt;
 | fillnull value="Not Patched"&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 20:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-replace-any-multi-values-found-in-search-result-with-true/m-p/430806#M123153</guid>
      <dc:creator>vinaykataaig</dc:creator>
      <dc:date>2019-08-07T20:42:51Z</dc:date>
    </item>
  </channel>
</rss>

