Splunk Search

ignore a line in splunk payload if a variable is null

guru333
Engager

Hi,

I want to ignore below line inside splunk alerts payload if email address is not provided buy user.

"action.email.to": {email},

 

What is best way to do this and if /else statement inside payload throws syntax error.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide more detail as to what exactly you are doing; your current description is too vague to determine how to advise you.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...