Splunk Search

How to use fit command together with foreach?

Wonjon
Observer

I would like to fit an ARIMA model to my data with a search something like this:

<base search>
| timechart span=5m avg(value) as value by some_field

The problem here is that, the number of field that returns by this search is dynamic, so it can return 5 fields one day but it could also return 3 or 7 the other day for instance.

I would like to fit an ARIMA model to all the fields that is returned by that search. What I found was the foreach command where you iterate over fields :

| foreach * [eval '<<FIELD>>' = ... ]

 

However, when I try to use the fit command instead of eval, I get an error message saying: 

Error in 'foreach' command: Search pipeline may not contain non-streaming commands

Since foreach cannot contain non-streaming commands.

 

Is there a way to come around this issue?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...