Splunk Search

How to create a dummy row if no data?

nwoolley
Engager

If there is no data for a table I want to create a row whilst waiting for the event to appear and add the word "Running" to the table until an event appears

to the query below

index=cronhost_billing sourcetype=run_billing ": SCRIPT" (group*) | rex field=_raw max_match=0 "[A-Z]+: (?
Tags (1)
0 Karma

adonio
Ultra Champion

try this:

   index=cronhost_billing sourcetype=run_billing ": SCRIPT" (group*) | rex field=_raw max_match=0 "[A-Z]+: (?
    |appendpipe [stats count| eval message="RUNNING"  | where count==0 |table message]

there are many answers in this portal regarding this, read here more:
https://answers.splunk.com/answers/50379/table-message-when-no-results-found.html
https://answers.splunk.com/answers/660786/how-to-handle-gracefully-no-results-found.html

note, your regex broke due to special characters, next time use the 101010 button when posting code

hope it helps

0 Karma

nwoolley
Engager

To expand - What I am trying to do is do a search for Today if there are no events that means the event has not completed so I want to create a row saying "Running" in the time column if there are no events so I guess I need an If statement and a method to create a dummy row if no data

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...