Splunk Search

Error in 'bin' command: The value for option span (-1s) is invalid.

sachinsingh2005
Explorer

I get the following error when I am taking the time and span value dynamically using tokens.

Error in 'bin' command: The value for option span (-1s) is invalid.
0 Karma
1 Solution

gyslainlatsa
Motivator

span is a time separator or time scale and therefore can not take negative values or 0. Try to select a time span=1s and you will see that you will not have this error message. Subsequently avoid negative or zero values in the token period, otherwise you will always have this error message.

View solution in original post

stephane_cyrill
Builder

This is a form where you have a search string like yours and an input text for the value of span. take a look .it may help you

<form>
  <label>duration</label>
  <fieldset submitButton="false">
    <input type="text" token="duration" searchWhenChanged="true"></input>
  </fieldset>
  <row>
    <panel>
      <chart>
        <search>
          <query>index=_internal|timechart span=$duration$ c</query>
        </search>
        <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
        <option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
        <option name="charting.axisTitleX.visibility">visible</option>
        <option name="charting.axisTitleY.visibility">visible</option>
        <option name="charting.axisTitleY2.visibility">visible</option>
        <option name="charting.axisX.scale">linear</option>
        <option name="charting.axisY.scale">linear</option>
        <option name="charting.axisY2.enabled">false</option>
        <option name="charting.axisY2.scale">inherit</option>
        <option name="charting.chart">column</option>
        <option name="charting.chart.bubbleMaximumSize">50</option>
        <option name="charting.chart.bubbleMinimumSize">10</option>
        <option name="charting.chart.bubbleSizeBy">area</option>
        <option name="charting.chart.nullValueMode">gaps</option>
        <option name="charting.chart.sliceCollapsingThreshold">0.01</option>
        <option name="charting.chart.stackMode">default</option>
        <option name="charting.chart.style">shiny</option>
        <option name="charting.drilldown">all</option>
        <option name="charting.layout.splitSeries">0</option>
        <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
        <option name="charting.legend.placement">right</option>
      </chart>
    </panel>
  </row>
</form>
0 Karma

gyslainlatsa
Motivator

span is a time separator or time scale and therefore can not take negative values or 0. Try to select a time span=1s and you will see that you will not have this error message. Subsequently avoid negative or zero values in the token period, otherwise you will always have this error message.

gyslainlatsa
Motivator

hi sachinsingh2005,
please send me your file many_sourcetypes.csv atgyslainko@gmail.com, i am try to check your query
thanks,
please forgive my english

0 Karma

sachinsingh2005
Explorer

Hi gyslainlatsa,

I know this and i am not giving any negative value there.

i am giving there "5s" and after clicking on search button it is giving me this error. i don't know why this is coming.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...