Exam SPLK-1002 Topic 1 Question 207 Discussion
Actual exam question for Splunk's SPLK-1002 exam
Question #: 207
Topic #: 1
Question #: 207
Topic #: 1
Given the following eval statement:
...| eval fieldl - if(isnotnull(fieldl),fieldl,0), field2 = if(isnull<field2>, "NO-VALUE", fieid2) Which of the following is the equivalent using f ilinull?
...| eval fieldl - if(isnotnull(fieldl),fieldl,0), field2 = if(isnull<field2>, "NO-VALUE", fieid2) Which of the following is the equivalent using f ilinull?
Suggested Answer: B Vote an answer
The fillnull command replaces null values in one or more fields with a specified value. The values option allows you to specify a comma-separated list of values to fill the null values in the corresponding fields. The fields option allows you to specify a comma-separated list of fields to apply the fillnull command to. The eval statement in the question uses the if and isnull functions to check if field1 and field2 have null values and replace them with 0 and "NO-VALUE" respectively. The equivalent expression using fillnull is to use the values option to specify 0 and "NO-VALUE" and the fields option to specify field1 and field22
1: Splunk Core Certified Power User Track, page 9. 2: Splunk Documentation, fillnull command.
1: Splunk Core Certified Power User Track, page 9. 2: Splunk Documentation, fillnull command.
by sos0tezikyk3 at Apr 29, 2025, 10:30 AM
0
0
0
10
Comments
sos0tezikyk3
2025-04-29 10:30:38| fillnull field1 | fillnull value="NO-VALUE" field2
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).