Splunk Search

drop null value

riqbal47010
Path Finder

I have below query
index=f5 partition="/Common/-" | rex "Username\s+'(?(.*))'" | eval Username=coalesce(Username, user)

username is there but first attempt he left empty and in second try he add his username. so the Username is showing null values whereas the default user field is showing actual username.

I am using coalesce because I want to take either value but it should not be null. How can I achieve this.

0 Karma
1 Solution

manjunathmeti
Champion

Function coalesce assigns the value of user field only if Username field does not exist in that event. But here it is set as empty string (""). Use if instead. below will sets value to user if Username is blank else sets to Username.

index=f5 partition="/Common/-" | rex "Username\s+'(?<Username>.*)'"| eval Username=if(Username == "",  user, Username)

View solution in original post

0 Karma

to4kawa
Ultra Champion
index=f5 partition="/Common/-" 
| rex "Username\s+'(?<Username>\w+)'" 
| eval Username=coalesce(Username, user)

your REGEX .* match null value.
How about this?
If Username has -, REGEX is [\w\-]+.

0 Karma

manjunathmeti
Champion

Function coalesce assigns the value of user field only if Username field does not exist in that event. But here it is set as empty string (""). Use if instead. below will sets value to user if Username is blank else sets to Username.

index=f5 partition="/Common/-" | rex "Username\s+'(?<Username>.*)'"| eval Username=if(Username == "",  user, Username)
0 Karma

riqbal47010
Path Finder

alt text

0 Karma

riqbal47010
Path Finder

alt text

0 Karma

rmmiller
Contributor

Can you provide a sample event?
It sounds like your regular expression might not be working exactly as you expect.

0 Karma

riqbal47010
Path Finder

attaching for your kind consideration

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...