Splunk Enterprise

Fillnull value directly in Data Model

SIEMStudent
Path Finder

Hi Spunkers, I have a request by customer never faced before.

For one particular Data Model, the Email one, it is required that certaine filed are always populated, even if the logs have this fields empty and/or are not present. So for example it is required that the field subject is always filled; of course, if subject is not present in events, we have to fill it with a token, like the fillnullvalue function does.

The particular part is that the customer required that this filling is performed not at search time, with a fillnull command in search, but by the Data Model itself; so, for example, if a log from mail server arrive and it not contain the subject field and/or it is not populated, the DM must fill it with a token value and so, when a search is executed, subject will be already filled with this token.

My question is: is this possible to perform?

Labels (1)
0 Karma
1 Solution

SIEMStudent
Path Finder

Solved by myself: the point is switch from extracted field to a calculated field. 

View solution in original post

SIEMStudent
Path Finder

Solved by myself: the point is switch from extracted field to a calculated field. 

Get Updates on the Splunk Community!

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...

How to Troubleshoot our Splunk HEC Endpoint

This blog post is part of an ongoing series on OpenTelemetry. In this blog post, we will explore the best way ...