Splunk Search

How to populate a null field if certain field equals ***

smithjnick
Path Finder

Hi Folks

Have an issue where some of my log entries contain null fields in which i need to populate in order to run stats against.

From the csv dump below, dest_port is empty so i need to basically say:

where rule=SSH-ACL, polulate empty dest_port field with a value of 22
where rule=NTP-ACL, polulate empty dest_port field with a value of 123

thanks in advance.

alt text

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try case.

... | eval dest_port = case (rule=SSH-ACL AND isnull(dest_port), 22, rule=NTP-ACL AND isnull(dest_port), 123, 1==1, dest_port)
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try case.

... | eval dest_port = case (rule=SSH-ACL AND isnull(dest_port), 22, rule=NTP-ACL AND isnull(dest_port), 123, 1==1, dest_port)
---
If this reply helps you, Karma would be appreciated.
0 Karma

jpalacian
Path Finder

Well, I'd use this slightly modified version

 ... | eval dest_port = case (rule="SSH-ACL" AND isnull(dest_port), 22, rule="NTP-ACL" AND isnull(dest_port), 123, 1==1, dest_port)

smithjnick
Path Finder

Yep JP - that fixed the issue - those damn quotation marks.

thank you muchly and have a great weekend.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Should there be at the end “,1=1, dest_port)” ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes. Updated.

---
If this reply helps you, Karma would be appreciated.
0 Karma

smithjnick
Path Finder

Thank you Rich.

Not currently giving me the desired output but the case command has now given me some food for thought. Thank you for the pointer and will report back with my outcome.

cheers

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...