Splunk Search

Quick Question: eval

wyang6
Path Finder

I have a chart:

Los Angeles   New York   Boston   Washington D.C.   Total
5             3                   2                 10

and

... | eval "x"='New York'+'Washington D.C'

returns x=5. However,

... | eval "x"='New York'+'Boston'+'Washington D.C'

returns an empty value, i.e. x=

How do I get around this problem where 'Boston' is empty?

Thank you.

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

use the ifisnull() or coalesce() function:

... | eval "x"=coalesce('New York',0)+coalesce('Boston',0)+ifisnull('Washington D.C',0,'Washington D.C')

Or you could use the | fillnull search command.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

use the ifisnull() or coalesce() function:

... | eval "x"=coalesce('New York',0)+coalesce('Boston',0)+ifisnull('Washington D.C',0,'Washington D.C')

Or you could use the | fillnull search command.

bwooden
Splunk Employee
Splunk Employee

I had

... | fillnull value=0 'Los Angeles' 'New York' 'Boston' 'Washington D.C.' | eval x='New York'+'Boston'+'Washington D.C'

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...