Splunk Enterprise

Fillnull value directly in Data Model

SIEMStudent
Path Finder

Hi Spunkers, I have a request by customer never faced before.

For one particular Data Model, the Email one, it is required that certaine filed are always populated, even if the logs have this fields empty and/or are not present. So for example it is required that the field subject is always filled; of course, if subject is not present in events, we have to fill it with a token, like the fillnullvalue function does.

The particular part is that the customer required that this filling is performed not at search time, with a fillnull command in search, but by the Data Model itself; so, for example, if a log from mail server arrive and it not contain the subject field and/or it is not populated, the DM must fill it with a token value and so, when a search is executed, subject will be already filled with this token.

My question is: is this possible to perform?

Labels (1)
0 Karma
1 Solution

SIEMStudent
Path Finder

Solved by myself: the point is switch from extracted field to a calculated field. 

View solution in original post

SIEMStudent
Path Finder

Solved by myself: the point is switch from extracted field to a calculated field. 

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...