I have encountered an issue with the foreach command on mv-fields.
When I execute my search, Splunk says: "Error in 'eval' command: The expression is malformed. An unexpected character is reached at '<<ITEM>>'. "
SPL to reproduce:
| makeresults
| eval mvfield=mvappend("1", "2", "3"), total=0
| foreach mode=multivalue mvfield
[eval total = total + <<ITEM>>]
| table mvfield, total
Note: this query is directly pulled from the examples for the foreach command.
Note2: the argument "mode" is not syntax-highlighted (would expect green)
Are using Splunk 9.0 or later? The mode option was not introduced until then.
FWIW, your query works as expected (including syntax highlighting) on my 9.0.0.1 system.
Are using Splunk 9.0 or later? The mode option was not introduced until then.
FWIW, your query works as expected (including syntax highlighting) on my 9.0.0.1 system.
No, I am not. Thank you for your reply.