Splunk Search

Non null number wildcard in search

dzolnjan
Engager

I got lines in log like these:
ERROR ((null))
...
ERROR (1553)
ERROR ((null))
...
ERROR (2139)
ERROR ((null))
...


I would like to filter only ones with actual number there, so results would be:
ERROR (1553)
ERROR (2139)


Thanks
Daniel

Tags (1)
0 Karma
1 Solution

markthompson
Builder

Hi @dzolnjan
Why not take advantage of the WHERE NOT clause.

search ERROR* AND WHERE NOT ERROR((null))

or something similar, I'm not totally sure on the syntax, haven't used it in a while.

View solution in original post

markthompson
Builder

Hi @dzolnjan
Why not take advantage of the WHERE NOT clause.

search ERROR* AND WHERE NOT ERROR((null))

or something similar, I'm not totally sure on the syntax, haven't used it in a while.

dzolnjan
Engager

Great it works, with just little a modify > "ERROR*" AND WHERE NOT "ERROR ((null))"

I didnt knew these clauses exist.

Thanks
Daniel

markthompson
Builder

Please vote up on my answer 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...