only thing i did was to make sure the spaces were available in the query which were updated in the calc metrics. Its just odd this had to be done this way...syntactically it was not wrong nor did Splunk flag as an error when running the query. just odd overall on behavior of this tool and a bit mindful going forward
... View more
I too have this same issue, @splunk / splunk team any response to this? i am having the issue to the point where my conditions are not being met and it defaults to another value defined in the case statement condition but the field it is looking does not have the matching value.
... View more