@ dreddy123
Can you please try this?
YOUR_SEARCH | rename courses{}.course as courses_course | where isnull(courses_course)
My Sample Search:
| makeresults | eval _raw="{\"id\":\"studentNumber\",\"courses\":[{\"course\" : \"Analysis of Alg\"},{\"course\": \"game dev\"}]}" | append [ | makeresults | eval _raw="{\"id\":\"studentNumber\",\"courses\":[]}" ] |kv | rename courses{}.course as courses_course | where isnull(courses_course)
Thanks
Does courses show up as a field in those events? If not, you can use | where isnull(courses)
{
"id":"studentNumber",
"courses" : [ ]
}
it will show up like this when no courses are registered.
To be a bit more specific, is courses extracted as a field and if so, what is the value?