I'm running a search (below) that has results that sometimes in certain fields will display in the gui as empty (null) but aren't. We I export the results I see "" as the value in the field. I've tried several things to populate this field with data so I can search on it but I've had no luck. Any thoughts / guidance is greatly appreciated. search string: | rest /servicesNS/-/-/saved/searches | where disabled=0 AND splunk_server="some_server" | fillnull value=na next_scheduled_time When I export the results and open in notepad, results are below: title,"cron_schedule","dispatch.earliest_time","dispatch.latest_time","alert.expires","next_scheduled_time",action "Access - Distinct Sources","","-48h@h",now,24h,"", "Access - Distinct Users","","-48h@h",now,24h,"",
... View more