Splunk Search

Why is ISNULL functionality not working?

Keerthi
Path Finder

Keerthi_0-1681721858028.png

I am trying to get the data only when my lastlogon(field name) is Null. but the above query is still giving me data for both Null and non Null values.

Labels (1)
0 Karma

woodcock
Esteemed Legend

Fields are case sensitive and also sometimes "empty" (i.e. == "").  You can check for both like this:

(isnull(LASTLOGON) OR LASTLOGON=="")

ITWhisperer
SplunkTrust
SplunkTrust

Field name are case-sensitive - try this

| where isnull(LASTLOGON)
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...