Splunk Search

Why does the split function fail for list_split_failure_1 and 2 but succeeds for list_split_success?

rkoster
Explorer
| makeresults count=1
| eval list_split_failure_1 = "fail:,searching old data:,searching new"
| eval list_split_failure_2 = "fail:,searching old ata:,searching new"
| eval list_split_success = "fail:,searching old qata:,searching old dta:,searching old ta:,searching new"
| eval list_split_failure_1 = split(list_split_failure_1, ",")
| eval list_split_failure_2 = split(list_split_failure_2, ",")
| eval list_split_success = split(list_split_success, ",")


Can someone help me to understand why the split function fails for list_split_failure_1 and 2 but succeeds for list_split_success?

Labels (1)
0 Karma
1 Solution

johnhuang
Motivator

This issue was discussed a while back and the consensus is that it's a bug introduced on 8.2.x+

https://community.splunk.com/t5/Splunk-Search/Multivalue-field-which-contains-the-string-quot-data-q...

 

View solution in original post

johnhuang
Motivator

This issue was discussed a while back and the consensus is that it's a bug introduced on 8.2.x+

https://community.splunk.com/t5/Splunk-Search/Multivalue-field-which-contains-the-string-quot-data-q...

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...