Getting Data In

Removing Blank/Empty events with Splunk

Dark_Ichigo
Builder

I have indexed a file that contains a number of blank event s with a timestamp, my goal is to remove those blank/Empty events by grouping them up and then "| delete" , what's the best way of doing this?

Note: these empty events have timestamp

0 Karma
1 Solution

Dark_Ichigo
Builder

I figured it out, as created a Regex that would locate a great amount of spaces after the timestamp into its own field, then I would search everything discarding that Field.

View solution in original post

Dark_Ichigo
Builder

I figured it out, as created a Regex that would locate a great amount of spaces after the timestamp into its own field, then I would search everything discarding that Field.

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...