Splunk Search

Search help

AKG11
Path Finder

Hi,

In a table, I am looking to get a field value from previous available value in case its null.

In below screenshot, dataset is basically  queries pulling out some DB records.  for same query events are spiltted in multiple events. (Incremental records)

Issue is query is not populating in each events. (Just 1st event) 
I am trying to fill the query value from 1st event to all subsequent

AKG11_0-1709304503784.pngAKG11_0-1709304503784.png

I have used streamstats which is almost working but skipping for some use case.

| streamstats current=f last(query) as previous_query reset_before="("match(query,\"\")")" by temp_field

AKG11_1-1709305337055.pngAKG11_1-1709305337055.png

 

May  be if we can logic to assign value where previous record is < current record and query is empty.

previous records

| streamstats current=f window=1 last(records) as pre_records reset_before="("match(query,\"\")")" by temp_field



Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the fillnull and filldown commands.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...