Splunk Search

URGENT REQUEST: how to pull specific values from given query?

iqbalintouch
Path Finder

sourcetype=abc "responseStatus=500" "abc.xyz.logging.yyyy.zzzzz" "cccccccccccccc88888883333hhhh" | rex field=_raw "\"customerBilledAmount\" : (?.?)," | rex field=_raw "\"resultID\" : (?.?)," | rex field=_raw "\"customerID\" : (?.*?)," | dedup resultID | table userrBilledAmount resultID customerID

Now I need to achieve
- exclude all null
- add up all userBilledAmount
- exclude all null from userBilledAmount only

0 Karma
1 Solution

493669
Super Champion

Hi @iqbalintouch, try below-

...|where isnotnull(userrBilledAmount)

This will remove null value field.
then you can use stats to add them like |stats sum(userrBilledAmount) as TotalAmount by customerID

View solution in original post

0 Karma

iqbalintouch
Path Finder

if I need to pull the data where userBilledAmount !=0.0 ??

how to achieve..your query has given near to desired output..

0 Karma

493669
Super Champion

Hi @iqbalintouch, try below-

...|where isnotnull(userrBilledAmount)

This will remove null value field.
then you can use stats to add them like |stats sum(userrBilledAmount) as TotalAmount by customerID

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...