Hi Community,
I need support to know how I can get the non-existent values from the two fields obtained from the "appendcols" command output.
Example of Splunk output in table format below:
1st_Field 2nd_Field
1111 2222
empty 3333
empty 1111
I am able to get 1111 after using the lookup command but I want to get 2222 and 3333 only as those are not present in 1st Field.
Ok so I created the two different outlookup in main search and appendcols subseach and then used lookup command. This solved my purpose.
You could append the lookup (inputlookup) and then remove the events which have had successful lookups i.e. values in 1st_Field