Splunk Search

Is there a way to replace values that say null with nothing?

lmmills
Explorer

We use Axonius to pull in identities.  When creating the the search some of the values come in with the word "null".  Is there a way to remove the word null and leave blank?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @lmmills,

did you tried with replace or fillnull?

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @lmmills,

did you tried with replace or fillnull?

Ciao.

Giuseppe

lmmills
Explorer

The replace did work I just had to list every field.  Thank you.

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...