Splunk Search

How to unset an input token when value isn't the default

vshakur
Path Finder

I have the following xml code:

   <change>
        <condition value="default_value">
           <unset token="some_token"></unset>
        </condition>
   </change>

I would like to unset some_token only when value DOESN'T equal "default_value".
I tried: condition value!="default_value" but it doesn't work and I get an error.

Thank you,
Samuel

0 Karma
1 Solution

sbbadri
Motivator

try this

<change>
<condition match="fieldname!=default_value">
<unset token="some_token"></unset>
</condition>
</change>

Check below link,
https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Viz/tokens

View solution in original post

sbbadri
Motivator

try this

<change>
<condition match="fieldname!=default_value">
<unset token="some_token"></unset>
</condition>
</change>

Check below link,
https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Viz/tokens

vshakur
Path Finder

It seems to be the right direction.
I just don't understand what should be the fieldname.
Should it be $current_token$? or a field from the input's search query?

0 Karma

sbbadri
Motivator

You need to use field from query. You haven't posted previous lines above change tag. So that i have mentioned as fieldname

0 Karma

vshakur
Path Finder

Great, thanks!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...