Hi,
I would like to know how to show all fields in the search even when results are all empty for some of the fields.
I've tried
| fillnull value="NA"
but that only works when there's at least a value in the empty field.
So, I would like splunk to show the following:
header 1 | header2 | header 3
value 1 | < empty > | value 3
value 1 | < empty > | value 3
value 1 | < empty > | value 3
value 1 | < empty > | value 3
value 1 | < empty > | value 3
I would appreciate for any suggestions on this.
Also, I understand that one can also possible do something like
| eval header2=""
but I have over 200 fields and about a handful of them are not filled out depending on situations and would hope to see if there's a better way to do this than listing all the header fields manually in the beginning.
Cheers!
... View more