Splunk Search

Multiple values - mvexpand not doing what I expect

dbcase
Motivator

Hi ,

I have a query that looks like this

earliest=-100hr index=blahalarm STATUS=readyArmed OR STATUS=ready OR STATUS=notReady|mvexpand notReady|mvexpand ready|mvexpand readyArmed|mvexpand _time|timechart span=1hr values(field2) by STATUS

but the resulting dataset comes back as this. I'm confused, why wouldn't mvexpand create multiple events?

alt text

0 Karma
1 Solution

dbcase
Motivator

FIxed it. My data was coming in with 15min increments but my span=1hr, once I set my span to 15min all is well

View solution in original post

0 Karma

dbcase
Motivator

FIxed it. My data was coming in with 15min increments but my span=1hr, once I set my span to 15min all is well

0 Karma

elliotproebstel
Champion

Doesn't the final timechart span=1h bring the events back into 1h buckets? The result looks like what I'd expect. Can you say more about what you're trying to achieve?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...