Getting Data In

Removing Blank/Empty events with Splunk

Dark_Ichigo
Builder

I have indexed a file that contains a number of blank event s with a timestamp, my goal is to remove those blank/Empty events by grouping them up and then "| delete" , what's the best way of doing this?

Note: these empty events have timestamp

0 Karma
1 Solution

Dark_Ichigo
Builder

I figured it out, as created a Regex that would locate a great amount of spaces after the timestamp into its own field, then I would search everything discarding that Field.

View solution in original post

Dark_Ichigo
Builder

I figured it out, as created a Regex that would locate a great amount of spaces after the timestamp into its own field, then I would search everything discarding that Field.

Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...