Splunk Search

How to ignore a field from search if the value is null, and then search based on the second input.?

kuriakose
Explorer

How to ignore a field from search if the value is null, search based on the second input.?
I have two inputs and this search will work only if i have some value in both the fields. I need the result, even if one value is null.

1.png

name="$field4$" OR EmpID="$field5$"

Found a similar one here,
but this did not resolve my issue.

Appreciate the help in advance.

https://community.splunk.com/t5/Getting-Data-In/How-to-omit-a-field-from-search-on-a-text-input-if-t...

Labels (1)
0 Karma

kuriakose
Explorer

I could sort out this issue by trying |search ($test1$ $test2$). 

Now the search is giving the results even if one input is null. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Doesn't this just do ($test1$ AND $test2$)?

0 Karma

kuriakose
Explorer

I have field values, name and EmpID in my index. The above search will not work if I am giving only a single input. I have to give both the inputs then only its working. which I don't want. Sometime I will have only one input.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try setting the default to * and/or in the change handler for the text input set a token to * if the input is empty and use those tokens in your search

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have your inputs set a new token which includes the name= if the value of the input is not empty otherwise set it to an empty string or perhaps unset it. Then use the whole of the new token(s) in your search.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...