Splunk Search

If specified field value does not exist in the current time period do this

splunk3341
Loves-to-Learn Lots

Hi, hoping to get some more insight on my current problem. My problem is the following 

I am using a where clause to capture data for a specific field value. If the specific value does not exist for the current time period I get the following message as a result 'No results found. Try expanding the time range.' Instead of the no results message showing up I would like to display something else. The following is an example.

index=sample_idex sourcetype="smf001"
| fields _time,  FIELD
| lookup sample_lookup.csv system as FIELD output sample_env
| eval e=if(in(sample_env, "env"), 1, 0)
| where e=1
| where FIELD=="value"
| table FIELD

I was thinking of doing something like the following with proper syntax:
| eval where FIELD=="value" else 

 

Labels (3)
Tags (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

You are already using if() function.  What is the difference between your pseudo code

| eval where FIELD=="value" else

and

index=sample_idex sourcetype="smf001"
| fields _time,  FIELD
| lookup sample_lookup.csv system as FIELD output sample_env
| eval e=if(in(sample_env, "env"), 1, 0)
| where e=1
| eval FIELD = if(FIELD == "value", FIELD, "display something else")
| table FIELD
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no "else" option to the where command.  The trick to solving this problem is to have a query that produces a result even if no events are found.  That's where the appendpipe command comes in handy.

index=sample_idex sourcetype="smf001"
| fields _time,  FIELD
| lookup sample_lookup.csv system as FIELD output sample_env
| eval e=if(in(sample_env, "env"), 1, 0)
| where e=1
| where FIELD=="value"
| appendpipe [ stats count | eval FIELD="something else" | where count=0 | fields - count ]
| table FIELD

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...