<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to filter row if some fields are empty? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668310#M229274</link>
    <description>&lt;LI-CODE lang="markup"&gt;| where isnotnull(vuln) OR isnotnull(score) OR isnotnull(company)&lt;/LI-CODE&gt;</description>
    <pubDate>Sat, 11 Nov 2023 10:23:13 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-11-11T10:23:13Z</dc:date>
    <item>
      <title>How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668285#M229258</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;How to filter all row if some fields are empty, but do not filter if one of the field has value?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;I appreciate your help. Thank you&lt;BR /&gt;&lt;BR /&gt;I want to filter out row, if vuln, score and company fields are empty/NULL&amp;nbsp; &amp;nbsp;&lt;BR /&gt;(All 3 fields are empty: Row 2 and 6 in the table below)&lt;BR /&gt;&lt;BR /&gt;If vuln OR company fields have values(NOT EMPTY), do not filter&amp;nbsp;&lt;BR /&gt;Row 4: vuln=Empty&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; company=company D(NOT empty)&lt;BR /&gt;Row 9: vuln=vuln9(NOT empty)&amp;nbsp; &amp;nbsp; company=empty&lt;BR /&gt;&lt;BR /&gt;If I use the search below, it will filter out row with vuln OR company that are empty (Row 4 and Row 9)&lt;BR /&gt;index=testindex&amp;nbsp; vuln=* AND score=* AND company=*&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Current data&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="365px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;STRONG&gt;no&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="90.6406px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="75.75px"&gt;&lt;STRONG&gt;vuln&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="59.875px"&gt;&lt;STRONG&gt;score&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="97.7344px"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;1&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln1&lt;/TD&gt;&lt;TD width="59.875px"&gt;9&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;2&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.2&lt;/TD&gt;&lt;TD width="75.75px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="59.875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="97.7344px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;3&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.3&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln3&lt;/TD&gt;&lt;TD width="59.875px"&gt;9&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;4&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.4&lt;/TD&gt;&lt;TD width="75.75px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="59.875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company D&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;5&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.5&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln5&lt;/TD&gt;&lt;TD width="59.875px"&gt;7&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;6&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.6&lt;/TD&gt;&lt;TD width="75.75px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="59.875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="97.7344px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;7&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.7&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln7&lt;/TD&gt;&lt;TD width="59.875px"&gt;5&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company G&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;8&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.8&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln8&lt;/TD&gt;&lt;TD width="59.875px"&gt;5&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company H&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;9&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.9&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln9&lt;/TD&gt;&lt;TD width="59.875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="97.7344px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;10&lt;/TD&gt;&lt;TD width="90.6406px"&gt;1.1.1.10&lt;/TD&gt;&lt;TD width="75.75px"&gt;vuln10&lt;/TD&gt;&lt;TD width="59.875px"&gt;4&lt;/TD&gt;&lt;TD width="97.7344px"&gt;company J&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Expected Result: ***NEED CORRECTION***&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="377px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;&lt;STRONG&gt;no&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;&lt;STRONG&gt;vuln&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;&lt;STRONG&gt;score&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln1&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;9&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.3&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln3&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;9&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;4&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.4&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company D&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;5&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.5&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln5&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;7&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;6&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;FILTERED&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;7&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.7&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln7&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;5&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company G&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;8&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.8&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln8&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;5&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company H&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;9&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.9&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln9&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px" height="25px"&gt;10&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;1.1.1.10&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;vuln10&lt;/TD&gt;&lt;TD width="80.125px" height="25px"&gt;4&lt;/TD&gt;&lt;TD width="95.625px" height="25px"&gt;company J&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Sorry, This is what I mean by FILTERED&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;STRONG&gt;no&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&lt;STRONG&gt;vuln&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&lt;STRONG&gt;score&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="95.625px"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;1&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln1&lt;/TD&gt;&lt;TD width="80.125px"&gt;9&lt;/TD&gt;&lt;TD width="95.625px"&gt;company A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;3&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.3&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln3&lt;/TD&gt;&lt;TD width="80.125px"&gt;9&lt;/TD&gt;&lt;TD width="95.625px"&gt;company C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;4&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.4&lt;/TD&gt;&lt;TD width="80.125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="95.625px"&gt;company D&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;5&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.5&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln5&lt;/TD&gt;&lt;TD width="80.125px"&gt;7&lt;/TD&gt;&lt;TD width="95.625px"&gt;company E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;7&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.7&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln7&lt;/TD&gt;&lt;TD width="80.125px"&gt;5&lt;/TD&gt;&lt;TD width="95.625px"&gt;company G&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;8&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.8&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln8&lt;/TD&gt;&lt;TD width="80.125px"&gt;5&lt;/TD&gt;&lt;TD width="95.625px"&gt;company H&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;9&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.9&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln9&lt;/TD&gt;&lt;TD width="80.125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="95.625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Sat, 11 Nov 2023 02:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668285#M229258</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-11T02:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668286#M229259</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval ip=if(isnull(vuln) AND isnull(score) AND isnull(company),"FILTERED",ip)
| eval vuln=if(ip="FILTERED",ip,vuln)
| eval score=if(ip="FILTERED",ip,score)
| eval company=if(ip="FILTERED",ip,company)&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 10 Nov 2023 23:10:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668286#M229259</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-10T23:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668298#M229268</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;Thank you for your help.&lt;BR /&gt;Your answer is correct, the output literally put "FILTERED".&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;Sorry if my original post is not clear. I corrected my post.&lt;BR /&gt;&lt;BR /&gt;What I meant by "filtered" , completely removed like shown below:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;STRONG&gt;no&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&lt;STRONG&gt;vuln&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&lt;STRONG&gt;score&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="95.625px"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;1&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln1&lt;/TD&gt;&lt;TD width="80.125px"&gt;9&lt;/TD&gt;&lt;TD width="95.625px"&gt;company A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;3&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.3&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln3&lt;/TD&gt;&lt;TD width="80.125px"&gt;9&lt;/TD&gt;&lt;TD width="95.625px"&gt;company C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;4&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.4&lt;/TD&gt;&lt;TD width="80.125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="80.125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="95.625px"&gt;company D&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;5&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.5&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln5&lt;/TD&gt;&lt;TD width="80.125px"&gt;7&lt;/TD&gt;&lt;TD width="95.625px"&gt;company E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;7&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.7&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln7&lt;/TD&gt;&lt;TD width="80.125px"&gt;5&lt;/TD&gt;&lt;TD width="95.625px"&gt;company G&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;8&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.8&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln8&lt;/TD&gt;&lt;TD width="80.125px"&gt;5&lt;/TD&gt;&lt;TD width="95.625px"&gt;company H&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;9&lt;/TD&gt;&lt;TD width="80.125px"&gt;1.1.1.9&lt;/TD&gt;&lt;TD width="80.125px"&gt;vuln9&lt;/TD&gt;&lt;TD width="80.125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="95.625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I figured it out&lt;BR /&gt;&lt;SPAN&gt;index=testindex&amp;nbsp; (vuln=* AND score=* AND company=*) OR (vuln=*) OR NOT (company="")&lt;BR /&gt;It's just weird that company=* does not work and I had to use NOT (company="") to filter out empty&amp;nbsp;&lt;BR /&gt;NOT isnull(company) also doesn't work&lt;BR /&gt;&lt;BR /&gt;Please suggest.&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 02:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668298#M229268</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-11T02:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668305#M229273</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254242"&gt;@LearningGuy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the solution to your "Expected Result" is the one hinted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Instead you can have to the last table simply adding&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(vuln=* OR company=*)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to you main search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2023 06:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668305#M229273</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-11T06:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668310#M229274</link>
      <description>&lt;LI-CODE lang="markup"&gt;| where isnotnull(vuln) OR isnotnull(score) OR isnotnull(company)&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 11 Nov 2023 10:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668310#M229274</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-11T10:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668376#M229296</link>
      <description>&lt;P&gt;I found solution for this:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;index=testindex&amp;nbsp; (vuln=* AND score=* AND company=*) OR (vuln=*) OR NOT (company="")&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;(vuln=* AND score=* AND company=*)&amp;nbsp; &amp;nbsp;==&amp;gt;&amp;nbsp; &amp;nbsp;condition for vuln, score, company exists&lt;BR /&gt;(vuln=*)&amp;nbsp; ==&amp;gt; condition for only vuln exists&lt;BR /&gt;NOT (company="") ==&amp;gt; condition for only company exists&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;company=*&amp;nbsp; &amp;nbsp;"&lt;STRONG&gt;is equivalent with"&amp;nbsp;&lt;/STRONG&gt; NOT (company="")&amp;nbsp; &amp;nbsp; &amp;nbsp;"&lt;STRONG&gt;is equivalent with"&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;isnull(company)&lt;BR /&gt;&lt;BR /&gt;any idea why &lt;STRONG&gt;company=*&lt;/STRONG&gt;&amp;nbsp; or &lt;STRONG&gt;isnull(company)&lt;/STRONG&gt; does not work?&lt;BR /&gt;Thank you&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 00:08:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668376#M229296</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-13T00:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668379#M229297</link>
      <description>&lt;P&gt;Empty and null are different things. If the field is "" then it is not null, so I use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where len(company)&amp;gt;0&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 13 Nov 2023 01:30:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668379#M229297</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-11-13T01:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668429#M229313</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello,&lt;BR /&gt;Thank you for your help.&lt;BR /&gt;&lt;BR /&gt;When I use one condition, it worked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where len(company)&amp;gt;0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1) but when I combined "len", it didn't work - "&lt;SPAN&gt;The search job has failed due to an error.&amp;nbsp;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where isnotnull(vuln) AND isnotnull(score) AND len(company&amp;gt;0) &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2) Why can't I use&amp;nbsp; len function without "where"?&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;3) Can I use company=* to include "exist/non empty"?&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It looks like * also didn't work&lt;BR /&gt;&lt;BR /&gt;Please suggest. Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 14:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668429#M229313</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-13T14:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668431#M229315</link>
      <description>&lt;P&gt;You have a typo&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where isnotnull(vuln) AND isnotnull(score) AND len(company) &amp;gt; 0&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 13 Nov 2023 14:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668431#M229315</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-13T14:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668438#M229319</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;Thanks for your correction and your help.&lt;BR /&gt;So this is what I am looking for:&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where (isnotnull(vuln) AND isnotnull(score) AND len(company)&amp;gt;0)) OR (isnotnull(vuln)) OR len(company&amp;gt;0)&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Any idea why * didn't work?&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;It seems like "&lt;STRONG&gt;where&lt;/STRONG&gt;" is faster than "&lt;STRONG&gt;search&lt;/STRONG&gt;"&amp;nbsp;&lt;BR /&gt;Thank you&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668438#M229319</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-13T15:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter row if some fields are empty?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668440#M229320</link>
      <description>&lt;P&gt;* doesn't work (as a wildcard) for where only search&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-row-if-some-fields-are-empty/m-p/668440#M229320</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-13T15:46:08Z</dc:date>
    </item>
  </channel>
</rss>

