Is there anyone who can explain me strange behaivor of "values" function. I created statistic by "stats" with "values" function and it returned mvfield as I expected, but there was in one line where values in mvfield were separated by comma not by newline. I attached a screenshot of this.
I tested on Splunk 8.2.7 and 9.0.0.
If I replace colon in field "source" by something else, the behavior change.Search_ Splunk_8.2.7.png
Yes, there is some problem with displaying mvfields and it manifests itself from time to time in this weird way in the ui.
Try adding something like
| eval c=mvcount(data) | eval first=mvindex(data,1)
It should still work properly, returning a count of 3 and your first value from that field.
Thank you for your reply. I think it is not for first time when I have seen it. There must be some small bug. I know that field is still mvfield and it behaves like that.
(: is the start of a construct in regex so perhaps this is the source of the issue. Try changing the replace to use (\:
I tried the change and It does not help. You can se on first screenshot.Search_ Splunk_8.2.7_1.png
You were right that the trigger could be the colon. If I remove the ":" from field and calculate the stat then all mvfield displayed the same way.Search_ Splunk_8.2.7_2.png
It doesn't completely solve my problem.