Splunk Search

Pls help me with JOIN to have columns


i have two columns A and B.
i have values in A column for all rows and B column has some values in rows.
i want to join where B column should replace the values in A columns and if B is empty value it should retain column A value
pls see below columns reference. i want output like c column
aa bbc bbc
123 321 321
1234 1234
325 325

0 Karma

Ultra Champion

Try coalesce

,your search>|eval C=coalesce(B,A)

If my comment helps, please give it a thumbs up!
0 Karma


Hi premranjithj,
Can you try below eval if it helps you
index=xyz| eval c=case(if(B="*", "B", B="", "A"))

0 Karma

Super Champion

Try this!

| eval c=if(B!="*",B,A)

Let me know if it helps!

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...