Splunk Search

lookup - append only columns with values

fedejko
Explorer

Hi,

I've got a lookup with a number of records, and not all of them have all columns populated. Is there a way to append only those columns which are not empty?

Something similar to:

 

| lookup mylookup lookup_key OUTPUTNEW list of columns to append
| <some SPL here to hide columns which are empty>

 

I'd be grateful for any tips.  I was experimenting with foreach but with no results.

Regards

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...