Splunk Search

Specify span option value in bin command with map

elensare
Engager

I try to use lookup to specify span option value in bin command with map

 

| inputlookup mylookupup.csv
| fields Index, SearchString ,Tdiv | map
[ search index="$Index$" _raw="*$SearchString$*"
| bin span="$Tdiv$" _time]

 

The previous request fails with  : 

Error in 'bin' command: The value for option span (Tdiv) is invalid. When span is expressed using a sub-second unit (ds, cs, ms, us), the span value needs to be < 1 second, and 1 second must be evenly divisible by the span value.

Example of values in Tdiv field :

  • 15m
  • 1h

could you help me with this problem?

Labels (1)
Tags (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I think I've seen this somewhere. For some reason map sometimes behaves differently if the search is specified in square brackets and differently if it's passed as parameter to the search= option.

Try the latter form (remembering about proper escaping)

| inputlookup mylookupup.csv
| fields Index, SearchString ,Tdiv | map search="search index=\"$Index$\" _raw=\"*$SearchString$*\"
| bin span=\"$Tdiv$\" _time"

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...