Splunk Search

How to query two nullable nested fields are not equal? [newbie question]

roliu
New Member

Hi, 

I have a dataset like below

 

 

[
  {classificationA: null, classificationB: null},
  {classificationA: {name: 'Education'}, classificationB: {name: 'Education'}},
  {classificationA: {name: 'IT'}, classificationB: {name: 'IT'}}
} 

 

 

My aim is to find all the rows whose classificationA is not equals to classificationB. So given the above dataset, it should return zero rows.

I thought it should be:

 

 

 | where classficationA != classficationB

 

 

But it is not working.  Anyone can help? Thank you!

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Is that your 'raw' data - it is not valid JSON. Is that a single event or 3 events?

Please share the raw data - if it's 3 classifications inside a single event, then please paste an example of the true _raw element of the value of a field that's extracted

 

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...