Splunk Search

Look for field. If doesn't exist, add

Becherer
Explorer

I am looking to have a eval search that looks for a field name of "Name" and adds the value. If the field doesn't exist, I want to add a field of "Name" and add "N/A" for the data. 

 

| eval Name = if((like(Name,"*"))),"&Name&","N/A")

 

This might be the wrong way of doing it.

 

Event example #1:

HostnameTimeNameAction
Server0211:22amjdoelogon
Server201:30pmjsmithlogon

 

Event example #2:

HostnameTimeAction 
Workstation10:45amSaved 
Workstation 10012:30pmSaved 

 

 

After the search is run I want the data to look like this.

 

HostnameTimeNameAction
Server0211:22amjdoelogon
Server201:30pmjsmithlogon
Workstation10:45amN/ASave
Workstation 10012:30pmN/ASave
    
Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| fillnull value="N/A" Name
0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...