Is there anyone who can explain me strange behaivor of "values" function. I created statistic by "stats" with "values" function and it returned mvfield as I expected, but there was in one line where values in mvfield were separated by comma not by newline. I attached a screenshot of this.
I tested on Splunk 8.2.7 and 9.0.0.
If I replace colon in field "source" by something else, the behavior change.
Yes, there is some problem with displaying mvfields and it manifests itself from time to time in this weird way in the ui.
Try adding something like
| eval c=mvcount(data) | eval first=mvindex(data,1)
It should still work properly, returning a count of 3 and your first value from that field.
Thank you for your reply. I think it is not for first time when I have seen it. There must be some small bug. I know that field is still mvfield and it behaves like that.
(: is the start of a construct in regex so perhaps this is the source of the issue. Try changing the replace to use (\:
I tried the change and It does not help. You can se on first screenshot.
You were right that the trigger could be the colon. If I remove the ":" from field and calculate the stat then all mvfield displayed the same way.
It doesn't completely solve my problem.