Splunk Search

How to exclude NULL lines in query for table results?

karlpena
Loves-to-Learn

Hello Team,

 

Trying to exclude NULL fields from results to avoid gaps in table. 

Currently using this query:
<my base search> | fillnull value="NULL" | search NOT NULL |table uid

 

and the results still table all the NULL spaces and only names them NULL as opposed to being blank. I want to only show the uids of the users.

any suggestions how I can get past this?

 

Thanks!

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Do you have a field or list of fields in mind?  For example, if some events do not have field "uid" - in Splunk search, uid value will be null.  To exclude them, simply do

uid=*
| table uid

In search command, <field>=* ensures that there is a non-null value.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...