Splunk Search

Search help

AKG11
Path Finder

Hi,

In a table, I am looking to get a field value from previous available value in case its null.

In below screenshot, dataset is basically  queries pulling out some DB records.  for same query events are spiltted in multiple events. (Incremental records)

Issue is query is not populating in each events. (Just 1st event) 
I am trying to fill the query value from 1st event to all subsequent

AKG11_0-1709304503784.png

I have used streamstats which is almost working but skipping for some use case.

| streamstats current=f last(query) as previous_query reset_before="("match(query,\"\")")" by temp_field

AKG11_1-1709305337055.png

 

May  be if we can logic to assign value where previous record is < current record and query is empty.

previous records

| streamstats current=f window=1 last(records) as pre_records reset_before="("match(query,\"\")")" by temp_field



Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the fillnull and filldown commands.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...