Dear Splunk Community, I'm trying to extract a list of changed fields, but they should only be listed if they have a value. <mysearch> | eval _raw="DeviceName:" . host ."
" . if(len(srcaddr)>0,"PolicySrc:" . srcaddr,"") ."
" . if(len(dstaddr)>0,"PolicyDst:" . dstaddr,"") ."
" . if(len(service)>0,"PolicySvc:" . service,"") ." With len>0 I managed to hide the fields that have not changed, but in the results they are still there as a line break, e.g. DeviceName: test
PolicyDst: dest1
PolicySvc svc1 How can I get rid of these line break(s)?
... View more