Splunk Search

Multiple values - mvexpand not doing what I expect

dbcase
Motivator

Hi ,

I have a query that looks like this

earliest=-100hr index=blahalarm STATUS=readyArmed OR STATUS=ready OR STATUS=notReady|mvexpand notReady|mvexpand ready|mvexpand readyArmed|mvexpand _time|timechart span=1hr values(field2) by STATUS

but the resulting dataset comes back as this. I'm confused, why wouldn't mvexpand create multiple events?

alt text

0 Karma
1 Solution

dbcase
Motivator

FIxed it. My data was coming in with 15min increments but my span=1hr, once I set my span to 15min all is well

View solution in original post

0 Karma

dbcase
Motivator

FIxed it. My data was coming in with 15min increments but my span=1hr, once I set my span to 15min all is well

0 Karma

elliotproebstel
Champion

Doesn't the final timechart span=1h bring the events back into 1h buckets? The result looks like what I'd expect. Can you say more about what you're trying to achieve?

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...