<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Appending Sparkline through a JOIN in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64113#M15864</link>
    <description>&lt;P&gt;For us it seems 7.1 has broken the |makemv solution, and removing it doesn't help. I cannot get the sparkline to render if it is in the second part of the join. I was able to work around it by switching the order and having the sparkline before the join.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jun 2018 14:34:16 GMT</pubDate>
    <dc:creator>the0duke0</dc:creator>
    <dc:date>2018-06-22T14:34:16Z</dc:date>
    <item>
      <title>Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64106#M15857</link>
      <description>&lt;P&gt;Good morning!&lt;/P&gt;

&lt;P&gt;I'm about to dive into the JS on this to discover how its rendered but in the meantime I thought I'd throw it out here to see if anyone else has come across this..&lt;/P&gt;

&lt;P&gt;Imagine a pretty basic search, all I'm doing is pulling back blocked events, no transactions or any funny business.. then I have a brainwave and decide to append a sparkline of blocked events for the same queue. This way I get a timestamp of the most recent block event with a mini timeline of previous blockages...&lt;/P&gt;

&lt;P&gt;However, the sparkline is generated in a subsearch (within a join command) and when its passed back it isn't being rendered as a sparkline but instead as the markup for it.&lt;/P&gt;

&lt;P&gt;Screenshot below, if anyone has come across this I'd be interested to know, otherwise I guess its just a bug/limitation of sparkline at the moment.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/sparklines.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;EDIT: Its worth pointing out that this does work if you reverse it and generate the sparkline first and then append the _time, but I'm interested in the problem now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2012 09:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64106#M15857</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-12-14T09:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64107#M15858</link>
      <description>&lt;P&gt;I saw a different situation where a sparkline was being displayed as its text markup rather than as a graphic.  In my case it turned out that the sparkline field had ceased to be a multi-valued field.  You can make it multi-valued again by appending this to the end of your search (or at least after the join):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makemv delim="," setsv=true sparkline
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As I said, the situation where I saw the problem was completely different to yours, so maybe this won't solve your case, but it worked for me.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2012 13:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64107#M15858</guid>
      <dc:creator>dmr195</dc:creator>
      <dc:date>2012-12-18T13:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64108#M15859</link>
      <description>&lt;P&gt;This did work to correct the sparkline rendering for my search that involved "| join"&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2013 21:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64108#M15859</guid>
      <dc:creator>hazekamp</dc:creator>
      <dc:date>2013-02-12T21:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64109#M15860</link>
      <description>&lt;P&gt;Situation same as on OP's screenshot -- after join of savedsearch with sparklines, got a column of raw data. Solution worked.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2013 12:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64109#M15860</guid>
      <dc:creator>abchernin</dc:creator>
      <dc:date>2013-03-06T12:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64110#M15861</link>
      <description>&lt;P&gt;Very good.&lt;BR /&gt;
I ran to my well.&lt;BR /&gt;
Thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 21:54:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64110#M15861</guid>
      <dc:creator>jrodriguezap</dc:creator>
      <dc:date>2013-08-06T21:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64111#M15862</link>
      <description>&lt;P&gt;Works great. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2014 02:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64111#M15862</guid>
      <dc:creator>troybebee</dc:creator>
      <dc:date>2014-07-15T02:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64112#M15863</link>
      <description>&lt;P&gt;We just upgraded to 7.x.  It appears that they resolved the rendering issue as I no longer need to use the |makev * solution.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 11:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64112#M15863</guid>
      <dc:creator>mschellhouse</dc:creator>
      <dc:date>2018-06-11T11:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64113#M15864</link>
      <description>&lt;P&gt;For us it seems 7.1 has broken the |makemv solution, and removing it doesn't help. I cannot get the sparkline to render if it is in the second part of the join. I was able to work around it by switching the order and having the sparkline before the join.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 14:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64113#M15864</guid>
      <dc:creator>the0duke0</dc:creator>
      <dc:date>2018-06-22T14:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64114#M15865</link>
      <description>&lt;P&gt;Same problem here with Splunk 7.1.1&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 09:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64114#M15865</guid>
      <dc:creator>swaro_ck</dc:creator>
      <dc:date>2018-06-25T09:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64115#M15866</link>
      <description>&lt;P&gt;I had the same issue in 7.1.2, removing setsv=true fixed it for me&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 20:42:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64115#M15866</guid>
      <dc:creator>andymcdowall</dc:creator>
      <dc:date>2018-08-27T20:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Appending Sparkline through a JOIN</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64116#M15867</link>
      <description>&lt;P&gt;I can confirm that if you remove setsv=true it will fix this issue&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 13:15:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Appending-Sparkline-through-a-JOIN/m-p/64116#M15867</guid>
      <dc:creator>ktvrznik</dc:creator>
      <dc:date>2018-12-13T13:15:36Z</dc:date>
    </item>
  </channel>
</rss>

