Splunk Search

Appending Sparkline through a JOIN


Good morning!

I'm about to dive into the JS on this to discover how its rendered but in the meantime I thought I'd throw it out here to see if anyone else has come across this..

Imagine a pretty basic search, all I'm doing is pulling back blocked events, no transactions or any funny business.. then I have a brainwave and decide to append a sparkline of blocked events for the same queue. This way I get a timestamp of the most recent block event with a mini timeline of previous blockages...

However, the sparkline is generated in a subsearch (within a join command) and when its passed back it isn't being rendered as a sparkline but instead as the markup for it.

Screenshot below, if anyone has come across this I'd be interested to know, otherwise I guess its just a bug/limitation of sparkline at the moment.

alt text

EDIT: Its worth pointing out that this does work if you reverse it and generate the sparkline first and then append the _time, but I'm interested in the problem now 🙂

0 Karma


I saw a different situation where a sparkline was being displayed as its text markup rather than as a graphic. In my case it turned out that the sparkline field had ceased to be a multi-valued field. You can make it multi-valued again by appending this to the end of your search (or at least after the join):

| makemv delim="," setsv=true sparkline

As I said, the situation where I saw the problem was completely different to yours, so maybe this won't solve your case, but it worked for me.

Path Finder

We just upgraded to 7.x. It appears that they resolved the rendering issue as I no longer need to use the |makev * solution.

0 Karma

Path Finder

For us it seems 7.1 has broken the |makemv solution, and removing it doesn't help. I cannot get the sparkline to render if it is in the second part of the join. I was able to work around it by switching the order and having the sparkline before the join.

0 Karma


I had the same issue in 7.1.2, removing setsv=true fixed it for me


I can confirm that if you remove setsv=true it will fix this issue

0 Karma

Path Finder

Same problem here with Splunk 7.1.1

0 Karma


Works great. Thanks!

0 Karma


Very good.
I ran to my well.
Thank you very much!

0 Karma


Situation same as on OP's screenshot -- after join of savedsearch with sparklines, got a column of raw data. Solution worked.

0 Karma


This did work to correct the sparkline rendering for my search that involved "| join"

Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...