Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why am I getting strange results with the fillnull command when I input a lookup table?

$
0
0
I have a search that looks like: multisearch [search a] [search b] | table field1, field2, field3 | fillnull value="N/A" | outputlookup lookup_table | tscollect namespace="Foo" When I input the lookup table, a whole bunch of fields still have null values. If I look at the same data using `tstats`, those fields have the "N/A" like they are supposed to. Can anyone explain why this is happening? Thx.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>