ExamGecko
Question list
Search
Search

Question 290 - SPLK-1002 discussion

Report
Export

Given the following eval statement:

... | eval field1 = if(isnotnull(field1),field1,0), field2 = if(isnull(field2), 'NO-VALUE', field2)

Which of the following is the equivalent using fillnull?

A.

... | fillnull values=(0,'NO-VALUE') fields=(field1,field2)

Answers
A.

... | fillnull values=(0,'NO-VALUE') fields=(field1,field2)

B.

There is no equivalent expression using fillnull

Answers
B.

There is no equivalent expression using fillnull

C.

... | fillnull field1 | fillnull value='NO-VALUE' field2

Answers
C.

... | fillnull field1 | fillnull value='NO-VALUE' field2

D.

... | fillnull value=0 field1 | fillnull field2

Answers
D.

... | fillnull value=0 field1 | fillnull field2

Suggested answer: D

Explanation:

The fillnull command can be used to replace null values in specific fields. The correct equivalent expression for the given eval statement would involve using fillnull twice, once for field1 to replace null values with 0, and once for field2 to replace null values with 'NO-VALUE'.

Splunk Docs - fillnull command

asked 18/10/2024
Jeff Benson
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first