Hi,
In a table, I am looking to get a field value from previous available value in case its null.
In below screenshot, dataset is basically queries pulling out some DB records. for same query events are spiltted in multiple events. (Incremental records)
Issue is query is not populating in each events. (Just 1st event)
I am trying to fill the query value from 1st event to all subsequent
I have used streamstats which is almost working but skipping for some use case.
| streamstats current=f last(query) as previous_query reset_before="("match(query,\"\")")" by temp_field
May be if we can logic to assign value where previous record is < current record and query is empty.
previous records
| streamstats current=f window=1 last(records) as pre_records reset_before="("match(query,\"\")")" by temp_field
Check out the fillnull and filldown commands.