Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why would data show up in _raw but not in search results after SEDCMD?

$
0
0
Hi there, I have several multivalue fields that are sometimes uneven. To make up for this, I'm trying to use SEDCMD to add a value anytime that value would otherwise be empty. Example before SEDCMD: FIELD 1 FIELD 2 1 2 data 3 Example before SEDCMD: FIELD 1 FIELD 2 1 -1 2 data 3 -1 So I have SEDCMD-fillvaluenull = s/"fields": {}/"fields": {"value":"-1"}/g And if I search for _raw then I see that it has successfully changed to -1, but when I search for fields.value it is not showing the -1, it only returns the data that I imported is what it seems.

Viewing all articles
Browse latest Browse all 47296

Trending Articles