Splunk Search

Adding a blank row to the output

arunkuriakose0
Engager

Hi Team

 

How can we add a blank row to the output. I have a search followed by some outputs in table format. I want to add a blank row in start or any where in the column .

index=*  Event Code=4624 Logotype=8  earliest=-d@d latest=@d | top user | appendpipe [|head 1 | for each * [eval new=""]] 

 

Tried something like this which gave me a new row with name new. I just want to add a blank row in search results. Can some one help?

Thanks in advance

 

Labels (2)
0 Karma

tscroggins
Influencer

@arunkuriakose0 

appendpipe [ | makeresults ]

will add a row/event with only a _time value.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...