Splunk Search

Non null number wildcard in search

dzolnjan
Engager

I got lines in log like these:
ERROR ((null))
...
ERROR (1553)
ERROR ((null))
...
ERROR (2139)
ERROR ((null))
...


I would like to filter only ones with actual number there, so results would be:
ERROR (1553)
ERROR (2139)


Thanks
Daniel

Tags (1)
0 Karma
1 Solution

markthompson
Builder

Hi @dzolnjan
Why not take advantage of the WHERE NOT clause.

search ERROR* AND WHERE NOT ERROR((null))

or something similar, I'm not totally sure on the syntax, haven't used it in a while.

View solution in original post

markthompson
Builder

Hi @dzolnjan
Why not take advantage of the WHERE NOT clause.

search ERROR* AND WHERE NOT ERROR((null))

or something similar, I'm not totally sure on the syntax, haven't used it in a while.

dzolnjan
Engager

Great it works, with just little a modify > "ERROR*" AND WHERE NOT "ERROR ((null))"

I didnt knew these clauses exist.

Thanks
Daniel

markthompson
Builder

Please vote up on my answer 🙂

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...