Hello Team,
Trying to exclude NULL fields from results to avoid gaps in table.
Currently using this query:
<my base search> | fillnull value="NULL" | search NOT NULL |table uid
and the results still table all the NULL spaces and only names them NULL as opposed to being blank. I want to only show the uids of the users.
any suggestions how I can get past this?
Thanks!
Do you have a field or list of fields in mind? For example, if some events do not have field "uid" - in Splunk search, uid value will be null. To exclude them, simply do
uid=*
| table uid
In search command, <field>=* ensures that there is a non-null value.