<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Bug &amp;quot;fields command&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346086#M102504</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;..... |fields - records2,records&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.text"&amp;gt;Number of Tickets&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 14 Jun 2017 14:32:33 GMT</pubDate>
    <dc:creator>wessam</dc:creator>
    <dc:date>2017-06-14T14:32:33Z</dc:date>
    <item>
      <title>Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346080#M102498</link>
      <description>&lt;P&gt;I am facing an issue with fields command as i am generating splunk queries below &lt;/P&gt;

&lt;P&gt;.....)|fields - records2,records&lt;/P&gt;

&lt;P&gt;and it working fine , however after automating this query on dashboard and running it several times , query is changed and became &lt;/P&gt;

&lt;P&gt;.....)|fields-records2,records&lt;/P&gt;

&lt;P&gt;Which gives an error because there is no spaces between characters !!&lt;BR /&gt;
So did anyone face the same issue and could you please help me with a workarround or solution &lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 11:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346080#M102498</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2017-06-14T11:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346081#M102499</link>
      <description>&lt;P&gt;What do you mean when by "automating" this query? What exactly did you do that seems to have resulted in removing whitespace in the query?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 12:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346081#M102499</guid>
      <dc:creator>rjthibod</dc:creator>
      <dc:date>2017-06-14T12:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346082#M102500</link>
      <description>&lt;P&gt;i mean that after the query in generated , i am just saving it into a dashboard and after opening this dashboard several times . whitespace in query is removed so that's weird as i have only saved the query&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 12:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346082#M102500</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2017-06-14T12:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346083#M102501</link>
      <description>&lt;P&gt;Can you share the XML for the dashboard?&lt;/P&gt;

&lt;P&gt;Also, what version of Splunk and what browser are you using?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 13:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346083#M102501</guid>
      <dc:creator>rjthibod</dc:creator>
      <dc:date>2017-06-14T13:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346084#M102502</link>
      <description>&lt;P&gt;Splunk Version 6.5.1 and i am using IE11&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 14:23:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346084#M102502</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2017-06-14T14:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346085#M102503</link>
      <description>&lt;P&gt;Can you share your XML for the dashboard?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 14:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346085#M102503</guid>
      <dc:creator>rjthibod</dc:creator>
      <dc:date>2017-06-14T14:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346086#M102504</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;..... |fields - records2,records&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.text"&amp;gt;Number of Tickets&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Jun 2017 14:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346086#M102504</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2017-06-14T14:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346087#M102505</link>
      <description>&lt;P&gt;Can you see what happens if you do the same thing in another browser (Chrome or FF)?  &lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 14:36:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346087#M102505</guid>
      <dc:creator>rjthibod</dc:creator>
      <dc:date>2017-06-14T14:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346088#M102506</link>
      <description>&lt;P&gt;I have been seeing this issue since we rolled out v6.5.x many weeks ago. I first encountered it when going in and out of the new Source edit feature, so I assume it  has to do with recompilation of XML. I believe I see the same thing when I go into Source via "Views". I also see it in titles where I use a dash--e.g. "Title - More Title". Our admin has been unable to address the issue or provide a workaround. Basically, I have found no workaround other than not using "fields -", or using "table ...". This is the first time I have finally seen anyone mention such a HUGE issue on Splunk Answers...which has surprised me a bit. I use MSIE.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 14:47:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346088#M102506</guid>
      <dc:creator>rmarcum</dc:creator>
      <dc:date>2017-06-14T14:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346089#M102507</link>
      <description>&lt;P&gt;I have been seeing this issue since we rolled out v6.5.x many weeks ago. I first encountered it when going in and out of the new Source edit feature, so I assume it  has to do with recompilation of XML. I believe I see the same thing when I go into Source via "Views". I also see it in titles where I use a dash--e.g. "Title - More Title". Our admin has been unable to address the issue or provide a workaround. Basically, I have found no workaround other than not using "fields -", or using "table ...". This is the first time I have finally seen anyone mention such a HUGE issue on Splunk Answers...which has surprised me a bit. I use MSIE.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 14:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346089#M102507</guid>
      <dc:creator>rmarcum</dc:creator>
      <dc:date>2017-06-14T14:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346090#M102508</link>
      <description>&lt;P&gt;BTW, another workaround I have for key code I do not want to change is to put it in a macro which seems to be immune to this issue. Again, I suspect "source".&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 15:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346090#M102508</guid>
      <dc:creator>rmarcum</dc:creator>
      <dc:date>2017-06-14T15:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346091#M102509</link>
      <description>&lt;P&gt;@rmarcum - please be sure to hit the "me-too" button if you want more eyes on the bug.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 15:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346091#M102509</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-06-14T15:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346092#M102510</link>
      <description>&lt;P&gt;We also see this with the sort command. Splunk 6.5.2&lt;/P&gt;

&lt;P&gt;You can verify this on the file system from $SPLUNK_HOME/etc/&lt;/P&gt;

&lt;P&gt;find ./users ./apps -type f -name '*.xml' -exec grep  --color 'sort-|find-' {} +&lt;/P&gt;

&lt;P&gt;I'm raising a support request for our users - I recommend you do the same&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 15:10:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346092#M102510</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2017-06-15T15:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346093#M102511</link>
      <description>&lt;P&gt;Support tell me this is fixed in 6.5.4&lt;/P&gt;

&lt;P&gt;See     SPL-140551 here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.4/ReleaseNotes/6.5.4"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.4/ReleaseNotes/6.5.4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 13:52:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346093#M102511</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2017-06-16T13:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346094#M102512</link>
      <description>&lt;P&gt;the same issue happened &lt;BR /&gt;
Is there any workaround for this bug instead of using fields -  ?&lt;/P&gt;

&lt;P&gt;index=xx |eval records='y'|stats values(records) as records list(y) as records2 by date_month|dedup records |eval records_after_dedup=mvcount(records), records_all=mvcount(records2)|fields - records2 records&lt;/P&gt;

&lt;P&gt;as i would like to display graph which represents number of records after dedup and all records before dedup.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346094#M102512</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2020-09-29T14:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346095#M102513</link>
      <description>&lt;P&gt;Is there any workaround for this bug instead of using fields -  ?&lt;/P&gt;

&lt;P&gt;index=xx |eval records='y'|stats values(records) as records list(y) as records2 by date_month|dedup records |eval records_after_dedup=mvcount(records), records_all=mvcount(records2)|fields - records2 records&lt;/P&gt;

&lt;P&gt;as i would like to display graph which represents number of records after dedup and all records before dedup.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346095#M102513</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2020-09-29T14:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346096#M102514</link>
      <description>&lt;P&gt;Is there any workaround for this bug instead of using fields -  ?&lt;/P&gt;

&lt;P&gt;index=xx |eval records='y'|stats values(records) as records list(y) as records2 by date_month|dedup records |eval records_after_dedup=mvcount(records), records_all=mvcount(records2)|fields - records2 records&lt;/P&gt;

&lt;P&gt;as i would like to display graph which represents number of records after dedup and all records before dedup.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346096#M102514</guid>
      <dc:creator>wessam</dc:creator>
      <dc:date>2020-09-29T14:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Bug "fields command"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346097#M102515</link>
      <description>&lt;P&gt;I have successfully used my two suggestions above (i.e., "table" or  put the code in a macro that contains the "fields -" command). Additionally, a real hack I sometimes use is a "focused" macro--e.g., FieldsMinus4 defined as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    fields - $field1$, $field2$, $field3$, $field4$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which I implement as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    | makeresults | eval aField1=123 | eval aField2=456 | eval aField3=789 | `FieldsMinus4(aField1,a,b,c)`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This takes advantage of the fields command working whether or not the field(s) exist that are passed as arguments. Thus I populate the 4 arguments using a, b, c, to make sure all 4 are there. This works for me for the many cases where there are less than 5 fields I need to remove. &lt;/P&gt;

&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 16:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Bug-quot-fields-command-quot/m-p/346097#M102515</guid>
      <dc:creator>rmarcum</dc:creator>
      <dc:date>2017-06-28T16:30:02Z</dc:date>
    </item>
  </channel>
</rss>

