Splunk Search

How to fill empty field with the time now

New Member

My search throws empty time-related fields and I want to fill that compo with the current time

0 Karma


Try adding this in to your search:

| eval now_time=now() | eval filled_time=coalesce(YourTimeFieldHere,now_time)|

Replace YourTimeFieldHere with whatever the name of your time-related field is. That should place the value of now() which is the current time into any empty value of your time field.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!