Splunk Search

Non null number wildcard in search

dzolnjan
Engager

I got lines in log like these:
ERROR ((null))
...
ERROR (1553)
ERROR ((null))
...
ERROR (2139)
ERROR ((null))
...


I would like to filter only ones with actual number there, so results would be:
ERROR (1553)
ERROR (2139)


Thanks
Daniel

Tags (1)
0 Karma
1 Solution

markthompson
Builder

Hi @dzolnjan
Why not take advantage of the WHERE NOT clause.

search ERROR* AND WHERE NOT ERROR((null))

or something similar, I'm not totally sure on the syntax, haven't used it in a while.

View solution in original post

markthompson
Builder

Hi @dzolnjan
Why not take advantage of the WHERE NOT clause.

search ERROR* AND WHERE NOT ERROR((null))

or something similar, I'm not totally sure on the syntax, haven't used it in a while.

dzolnjan
Engager

Great it works, with just little a modify > "ERROR*" AND WHERE NOT "ERROR ((null))"

I didnt knew these clauses exist.

Thanks
Daniel

markthompson
Builder

Please vote up on my answer 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...