Splunk Search

Why is the mvcombine breaking sparkline?

subtrakt
Contributor

Hi everyone,

I have a requirement to use mvcombine after stats.

When I use mvcombine the sparkline stops working and presents the sparkling number values instead of the line. Has anyone seen this before?

Also If I put mvcombine before stats it kills the sparkling. I think it has something to do with the lookup prior that uses the url field

| stats values(TEST1) as TEST1 sparkline by url
| mvexpand  TEST1 | eval TEST1=TEST1.”$” | mvcombine TEST1
Tags (3)
0 Karma

niketn
Legend

@subtrakt can you run the following query instead?

 | eval TEST1=TEST1."$"
 | stats values(TEST1) as TEST1 sparkline by url
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...