makeresults command: Examples
Examples for using the SPL2 makeresults command.
Generating identical events with the same timestamp
The following example generates 5 identical events, each with the same timestamp:
| makeresults 5The results look something like this:
| _time |
|---|
| 2025-11-09 14:35:58 |
| 2025-11-09 14:35:58 |
| 2025-11-09 14:35:58 |
| 2025-11-09 14:35:58 |
| 2025-11-09 14:35:58 |
Generally, events with identical timestamps isn't very useful. By combining the makeresults command with other commands, as shown in the next example, you can generate events with different timestamps.
Generat a set of events with different timestamps
You can use the makeresults command to create a series of events. This is most often used to test your search syntax. Start by creating the number of events and add the streamstats command create a field that assigns a number to each event. The following search creates a set of five results:
| makeresults count=5
| streamstats countThe results look something like this:
| _time | count |
|---|---|
| 2025-51-09 14:35:58 | 1 |
| 2025-11-09 14:35:58 | 2 |
| 2025-11-09 14:35:58 | 3 |
| 2025-11-09 14:35:58 | 4 |
| 2025-11-09 14:35:58 | 5 |
You can now use the count to create different dates in the _time field, using the eval command.
| makeresults count=5
| streamstats count
| eval _time=_time-(count*86400)The calculation multiplies the value in the count field by the number of seconds in a day. The result is subtracted from the original _time field to get new dates equivalent to 24 hours ago, 48 hours ago, and so forth. The seconds in the date are different because _time is calculated the moment you run the search.
The results look something like this:
| _time | count |
|---|---|
| 2025-11-08 14:45:24 | 1 |
| 2025-11-07 14:45:26 | 2 |
| 2025-11-06 14:45:28 | 3 |
| 2025-11-05 14:45:30 | 4 |
| 2025-11-04 14:45:32 | 5 |
The dates start from the day before the original date, 2025-11-09, and go back five days.
Need more than 5 results? Simply change the count value in the makeresults command.
See also
makeresults command