Splunk Search

split function in calculated fields

AlexeyNL
Explorer

When i try to save in Splunk Web calculated fields that contains split function i have a "Encountered the following error while trying to save: In handler 'props-eval': Bad function" message.
Why i can't use this function in calculated fields?
There is no word about this limitation here in Splunk Documentation,
Examples of Eval expression that are not working:

split(anyfield,";")

or

split("x:x",":")

But in conjunction with eval in Search these are working fine.

Splunk Version............................................6.0
Splunk Build............................................182037

Tags (3)

joebensimo
Path Finder

This appears to only be a limitation in the user interface. I have successfully added (and use) calculated fields that use split by directly adding them to a props.conf file.

For example:

[source::users*ly]
EVAL-userid = split(userid," ")

joebensimo
Path Finder

I too am having this problem when I use split is calculated fields. Eg: split(field," ")

0 Karma

mklunder
Explorer

I have also encountered the same issue. In my case I am adding the eval below in the web UI (6.0).

Expression:
mvcount( SPLIT(nodes, ",") )

Returns:
Encountered the following error while trying to save: In handler 'props-eval': Bad function

alacercogitatus
SplunkTrust
SplunkTrust

Can you edit and put your calculated input definition?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...