Splunk Enterprise

How to deal with lookup with empty columns?

woodentree
Communicator

Hi,

We have a huge lookup file with accounts’ data. Some of lookup’s columns has a value for each account, lake ‘username’ or ‘startdate’. However, another one may have no value at all, like ‘subcontractor’.

When we perform a search like subcontractor=company_A it works great, but when we perform a search like subcontractor=* it returns no result.

The only solution we were able to find is to use an eval function to create an empty value for every column:

 

| eval subcontractor =if(isnotnull(subcontractor), subcontractor,"")

 

It works but it doesn’t looks like the right way to do it, especially if you have dozens columns like this one. Do you now a better way to deal with lookup’s columns?

Thanks for the help.

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| fillnull value="N/A"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| fillnull value="N/A"

woodentree
Communicator

Exactly!

Thanks for the help.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...