Splunk Search

Search help

AKG11
Path Finder

Hi,

In a table, I am looking to get a field value from previous available value in case its null.

In below screenshot, dataset is basically  queries pulling out some DB records.  for same query events are spiltted in multiple events. (Incremental records)

Issue is query is not populating in each events. (Just 1st event) 
I am trying to fill the query value from 1st event to all subsequent

AKG11_0-1709304503784.png

I have used streamstats which is almost working but skipping for some use case.

| streamstats current=f last(query) as previous_query reset_before="("match(query,\"\")")" by temp_field

AKG11_1-1709305337055.png

 

May  be if we can logic to assign value where previous record is < current record and query is empty.

previous records

| streamstats current=f window=1 last(records) as pre_records reset_before="("match(query,\"\")")" by temp_field



Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the fillnull and filldown commands.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...