Splunk Search

How to get latest parameter from csv disregarding empty values

mishaaaaaaaaaa
Explorer

Hi splunk comunity!

I have dashboard with text input, which starts to execute when i change my parameter in text box, in query i write this parameter to my csv file.
In another dashboard i'm trying to read latest value of this parameter, but if i post an empty field in my first dashboard i get an empty result in my second.
So the question is how to check an empty value like method isEmpty() in java or how to ban empty fields passing to csv file in first dashboard?
Or how can i display last not empty value?

Tags (1)
0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@mishaaaaaaaaaa ,

Either use | where isnotnull(field) while reading or check with isnotnull(field) or isnull(field) before writing,

Reference : https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/InformationalFunctions

Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

@mishaaaaaaaaaa ,

Either use | where isnotnull(field) while reading or check with isnotnull(field) or isnull(field) before writing,

Reference : https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/InformationalFunctions

Happy Splunking!

mishaaaaaaaaaa
Explorer

@renjith.nair This doesn't work, i've already tryed something like this, but i still get an emty field in my second dushboard

| makeresults
| eval param="$firstParam$"
| eval parameter=if(isnull(param), 50, param)
| outputcsv append=true mishasTestParametrization.csv
| table parameter

| inputcsv mishasTestParametrization.csv
| stats latest(parameter) as latestParam

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

in that case, it might not be null() but just an empty space , try adding this

if(isnull(param) OR param=="", 50, param)

Happy Splunking!
0 Karma

mishaaaaaaaaaa
Explorer

@renjith.nair yes this works, but i understud that this is not what i want. I need to write to csv if my param is not empty and don't write if it's empty

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@mishaaaaaaaaaa ,
Same can be used in the outputlookup as well. Taking your example

| makeresults
| eval param="$firstParam$"
| where param!="" AND isnotnull(param)
| outputcsv append=true mishasTestParametrization.csv
Happy Splunking!
0 Karma

mishaaaaaaaaaa
Explorer

thanks a lot, that works perfect!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...