Splunk Search

Specify span option value in bin command with map

elensare
Engager

I try to use lookup to specify span option value in bin command with map

 

| inputlookup mylookupup.csv
| fields Index, SearchString ,Tdiv | map
[ search index="$Index$" _raw="*$SearchString$*"
| bin span="$Tdiv$" _time]

 

The previous request fails with  : 

Error in 'bin' command: The value for option span (Tdiv) is invalid. When span is expressed using a sub-second unit (ds, cs, ms, us), the span value needs to be < 1 second, and 1 second must be evenly divisible by the span value.

Example of values in Tdiv field :

  • 15m
  • 1h

could you help me with this problem?

Labels (1)
Tags (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I think I've seen this somewhere. For some reason map sometimes behaves differently if the search is specified in square brackets and differently if it's passed as parameter to the search= option.

Try the latter form (remembering about proper escaping)

| inputlookup mylookupup.csv
| fields Index, SearchString ,Tdiv | map search="search index=\"$Index$\" _raw=\"*$SearchString$*\"
| bin span=\"$Tdiv$\" _time"

 

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...