I'm new to Splunk, and I am trying to figure out how the eval command works in searches.
Sometimes I don't get any result, but no errors/warnings are generated (not even on any log files I can see).
How do I troubleshoot an 'eval' that does not produce anything?
For example, I was using a simple expression like:
sourcetype="rti_avdemo" | eval foo=action+1 | table action, foo
where I thought 'action' was a number. That did not produce anything. Then I figured out that 'action' is a multi-value.
In this case, eval does not produce anything, and I get no errors, warnings. How can I get some information that can help me ?
Thanks!
Fab
... View more