Splunk Search

How to exclude NULL lines in query for table results?

karlpena
Loves-to-Learn

Hello Team,

 

Trying to exclude NULL fields from results to avoid gaps in table. 

Currently using this query:
<my base search> | fillnull value="NULL" | search NOT NULL |table uid

 

and the results still table all the NULL spaces and only names them NULL as opposed to being blank. I want to only show the uids of the users.

any suggestions how I can get past this?

 

Thanks!

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Do you have a field or list of fields in mind?  For example, if some events do not have field "uid" - in Splunk search, uid value will be null.  To exclude them, simply do

uid=*
| table uid

In search command, <field>=* ensures that there is a non-null value.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...