Splunk Search

Search help

AKG11
Path Finder

Hi,

In a table, I am looking to get a field value from previous available value in case its null.

In below screenshot, dataset is basically  queries pulling out some DB records.  for same query events are spiltted in multiple events. (Incremental records)

Issue is query is not populating in each events. (Just 1st event) 
I am trying to fill the query value from 1st event to all subsequent

AKG11_0-1709304503784.png

I have used streamstats which is almost working but skipping for some use case.

| streamstats current=f last(query) as previous_query reset_before="("match(query,\"\")")" by temp_field

AKG11_1-1709305337055.png

 

May  be if we can logic to assign value where previous record is < current record and query is empty.

previous records

| streamstats current=f window=1 last(records) as pre_records reset_before="("match(query,\"\")")" by temp_field



Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the fillnull and filldown commands.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...