I'm sure I'm missing something simple, but I suddenly can't get the eval command to work. Simplest case, the following search never sets the test1 field.
index="*" | head 1 | eval test1 = 'splunk is driving me crazy' | table _time, test1
The _time field is populated, but test1 is always empty. Can anyone explain this to me?
Nevermind, I figured it out. It's the single quotes quietly failing.