i have been using this query but couldn't be able to remove null rows, please help me
index=Window_wash
| rex field=_raw "TIME.TAKEN.FOR.(?<Vendor>\w+)"
| rex field=_raw (?<Time_MS>\d+).ms
| timechart span=1m max(Time_MS) as Time_MS
| outlier Time_MS
Hi @Aj01,
did you tried with the where command?
index=Window_wash
| rex field=_raw "TIME.TAKEN.FOR.(?<Vendor>\w+)"
| rex field=_raw (?<Time_MS>\d+).ms
| timechart span=1m max(Time_MS) AS Time_MS
| where Time_MS>0
| outlier Time_MS
Ciao.
Giuseppe
Hi @gcusello
Thanks for helping, it worked i was using where Time_MS=* or Time_MS!=null but this worked
Thankyou
Hi @Aj01,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
Hi @Aj01,
did you tried with the where command?
index=Window_wash
| rex field=_raw "TIME.TAKEN.FOR.(?<Vendor>\w+)"
| rex field=_raw (?<Time_MS>\d+).ms
| timechart span=1m max(Time_MS) AS Time_MS
| where Time_MS>0
| outlier Time_MS
Ciao.
Giuseppe
Remember, search is used to compare fields to literals whereas where is used to compare fields to fields or expressions.
Sometimes both work. Sometimes not.
| search Time_MS>0
| where isnotnull(Time_MS)