Splunk Search

Why am I getting strange results with the fillnull command when I input a lookup table?


I have a search that looks like:

multisearch [search a] [search b] | table field1, field2, field3 | fillnull value="N/A" | outputlookup lookup_table | tscollect namespace="Foo"

When I input the lookup table, a whole bunch of fields still have null values. If I look at the same data using tstats, those fields have the "N/A" like they are supposed to.

Can anyone explain why this is happening?


0 Karma


I had a problem like your and I solved using eval
try this

eval myfield=if(isnull(myfield),"N/A",myfield)



0 Karma