Splunk Enterprise

Exclude Fields with null value from table

jt_yshi
Engager

Hello Splunk Community,

 

I am looking for some help.

 

I would like to make an audit of all fields where there is not NULL for a given event. Which means I want a table with all fields where the vaule is not NULL. The thing is I do not want to have to specify the fields as there are too many and I am creating an audit of all fields that have values. It would take too much time to specify the field names in the search and or table. Hence, I am looking for a solution that lists all fields != NULL

I tried: 

|fillnull value="NULL"
|search NOT "NULL"
|table*
 
and many other searches with metadata, metasearch and audit commands. I cannot seem to find the right syntax to exclude fields with a given field value eg NULL or simply empty ones.

 
Thank you in advance for you help!!
 
best,
julia 
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...