Splunk Search

use eval to return field that is not null?


i working on a query to display fields with data others than the string "NULL"..
and i am trying to use eval.

eval new_field=if(field1 !="NULL" "field1--".value1."field2--".value2, field2) 

then continue for the next eval.. then pipe to next eval.

However, i cannot get the result out.. is it my syntax error?

Tags (2)
0 Karma


I guess the separating comma is missing:

eval new_field=if(field1!="NULL","field1--".value1."field2--".value2, field2) 
0 Karma