Getting Data In

Removing Blank/Empty events with Splunk

Dark_Ichigo
Builder

I have indexed a file that contains a number of blank event s with a timestamp, my goal is to remove those blank/Empty events by grouping them up and then "| delete" , what's the best way of doing this?

Note: these empty events have timestamp

0 Karma
1 Solution

Dark_Ichigo
Builder

I figured it out, as created a Regex that would locate a great amount of spaces after the timestamp into its own field, then I would search everything discarding that Field.

View solution in original post

Dark_Ichigo
Builder

I figured it out, as created a Regex that would locate a great amount of spaces after the timestamp into its own field, then I would search everything discarding that Field.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...