Splunk Search

How to set a token when the field exists?

timgren
Path Finder

I'm looking for a way to set a token when the column exists (regardless of value).  
Tried these with no luck. 

<eval token=if(isnotnull($row.MyCol$),useValue=$row.MyCol$,null())>
<eval token=case($row.MyCol$ != &quot;&quot; , useValue=$row.MyCol$) 

Thoughts? 

Labels (1)
0 Karma
1 Solution

timgren
Path Finder

Not quite, but that led me to one that does. 
<eval token="MyCol">if(isnotnull($row.MyCol$),"UseValue=".$row.MyCol$,"")</eval> 

 

Thanks! 

View solution in original post

kamlesh_vaghela
SplunkTrust
SplunkTrust

@timgren 


You can also put logic in your search and display only the required columns by adding

| eval flag=if(isnull(MyCol),"0","1")
| eval flag_value=if(isnull(MyCol) AND MyCol!="" ,null(),MyCol)

 

and you can manage your tokens in drill down like this.

 

<drilldown>
          <condition match="$row.flag$=&quot;1&quot;">
            <set token="useValue">$row.flag_value$</set>
          </condition>
          <condition>
            <unset token="useValue" />
          </condition>
        </drilldown>

 

I hope this will help you.

Thanks
KV
If any of my replies help you to solve the problem Or gain knowledge, an upvote would be appreciated.

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried this?

<eval token=if(isnotnull($row.MyCol$), $row.MyCol$, null())>
---
If this reply helps you, Karma would be appreciated.

timgren
Path Finder

Not quite, but that led me to one that does. 
<eval token="MyCol">if(isnotnull($row.MyCol$),"UseValue=".$row.MyCol$,"")</eval> 

 

Thanks! 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...