Splunk Search

Multiple values - mvexpand not doing what I expect

dbcase
Motivator

Hi ,

I have a query that looks like this

earliest=-100hr index=blahalarm STATUS=readyArmed OR STATUS=ready OR STATUS=notReady|mvexpand notReady|mvexpand ready|mvexpand readyArmed|mvexpand _time|timechart span=1hr values(field2) by STATUS

but the resulting dataset comes back as this. I'm confused, why wouldn't mvexpand create multiple events?

alt text

0 Karma
1 Solution

dbcase
Motivator

FIxed it. My data was coming in with 15min increments but my span=1hr, once I set my span to 15min all is well

View solution in original post

0 Karma

dbcase
Motivator

FIxed it. My data was coming in with 15min increments but my span=1hr, once I set my span to 15min all is well

0 Karma

elliotproebstel
Champion

Doesn't the final timechart span=1h bring the events back into 1h buckets? The result looks like what I'd expect. Can you say more about what you're trying to achieve?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...