Splunk Search

Search help

AKG11
Path Finder

Hi,

In a table, I am looking to get a field value from previous available value in case its null.

In below screenshot, dataset is basically  queries pulling out some DB records.  for same query events are spiltted in multiple events. (Incremental records)

Issue is query is not populating in each events. (Just 1st event) 
I am trying to fill the query value from 1st event to all subsequent

AKG11_0-1709304503784.png

I have used streamstats which is almost working but skipping for some use case.

| streamstats current=f last(query) as previous_query reset_before="("match(query,\"\")")" by temp_field

AKG11_1-1709305337055.png

 

May  be if we can logic to assign value where previous record is < current record and query is empty.

previous records

| streamstats current=f window=1 last(records) as pre_records reset_before="("match(query,\"\")")" by temp_field



Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the fillnull and filldown commands.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Meet Duke Cyberwalker | A hero’s journey with Splunk

We like to say, the lightsaber is to Luke as Splunk is to Duke. Curious yet? Then read Eric Fusilero’s latest ...

The Future of Splunk Search is Here - See What’s New!

We’re excited to introduce two powerful new search features, now generally available for Splunk Cloud Platform ...

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...