如何从Splunk查询结果表格中移除空行?
解决Splunk查询中的空行问题
要移除timechart生成的空行,只保留TotalRecords有值的行,有两种直接的解决方法:
方法一:让timechart不生成空行
在timechart命令中添加useother=f和usenull=f参数,阻止命令生成无数据的时间区间行:
index=stg host="stg-host1" " Number of data processed for day is" | rex "(?<Records>[^\s]+) from file" | timechart max(Records) as TotalRecords span=45min useother=f usenull=f
方法二:过滤空值行
在timechart之后追加where命令,直接过滤掉TotalRecords为空的行:
index=stg host="stg-host1" " Number of data processed for day is" | rex "(?<Records>[^\s]+) from file" | timechart max(Records) as TotalRecords span=45min | where isnotnull(TotalRecords)
说明
useother=f:禁用“其他”类别行的生成usenull=f:禁用空值对应的时间区间行的生成where isnotnull(TotalRecords):直接筛选出TotalRecords字段非空的记录
内容的提问来源于stack exchange,提问作者Anand Somani
相关产品推荐
相关产品推荐

