Splunk Search

split function in calculated fields

AlexeyNL
Explorer

When i try to save in Splunk Web calculated fields that contains split function i have a "Encountered the following error while trying to save: In handler 'props-eval': Bad function" message.
Why i can't use this function in calculated fields?
There is no word about this limitation here in Splunk Documentation,
Examples of Eval expression that are not working:

split(anyfield,";")

or

split("x:x",":")

But in conjunction with eval in Search these are working fine.

Splunk Version............................................6.0
Splunk Build............................................182037

Tags (3)

joebensimo
Path Finder

This appears to only be a limitation in the user interface. I have successfully added (and use) calculated fields that use split by directly adding them to a props.conf file.

For example:

[source::users*ly]
EVAL-userid = split(userid," ")

joebensimo
Path Finder

I too am having this problem when I use split is calculated fields. Eg: split(field," ")

0 Karma

mklunder
Explorer

I have also encountered the same issue. In my case I am adding the eval below in the web UI (6.0).

Expression:
mvcount( SPLIT(nodes, ",") )

Returns:
Encountered the following error while trying to save: In handler 'props-eval': Bad function

alacercogitatus
SplunkTrust
SplunkTrust

Can you edit and put your calculated input definition?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...