<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pivot table filter flexibility? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107436#M22597</link>
    <description>&lt;P&gt;I know this thread is old but since I just had the same question I wanted to post my work around. Basically I added the filter on the base search. I know it may not be practical for all users but it worked for my use case. &lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2016 22:38:09 GMT</pubDate>
    <dc:creator>dasveruckte</dc:creator>
    <dc:date>2016-11-30T22:38:09Z</dc:date>
    <item>
      <title>Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107426#M22587</link>
      <description>&lt;P&gt;I have indexed a dataset that contains a collection of customer names, their purchases, their addresses, and other various bits of information that you might expect to see in a CRM database for a web store. I've also created a data model, a variety of objects within that data model, and I've assigned "auto-extracted" attributes to each of those objects. (This feature is awesome, BTW!)&lt;/P&gt;

&lt;P&gt;When I create a pivot, I've discovered that I can't figure out how to filter the pivot on more than one value of a particular attribute. For example, I'd like to be able to filter my pivot down to customers that reside in North Dakota, Hawaii, and Washington DC. Is it possible to create a pivot filter (without creating eval fields or using other GUI acrobatics outside the pivot interface itself) that will filter results for multiple values of a field (e.g. ND, HI, and/or DC)? When I configure multiple filters, they appear to be logically ANDed together. The result is that no entries are returned. What I'm looking for is the ability to logically OR those filters together.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2013 21:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107426#M22587</guid>
      <dc:creator>sspencer_splunk</dc:creator>
      <dc:date>2013-10-20T21:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107427#M22588</link>
      <description>&lt;P&gt;Have you tried setting up an object that uses a constraint search to ensure that it only includes events where customer = ND OR HI OR DC? As long as the customer field exists as an auto-extracted attribute in the data this should be doable. Then you could just build a pivot based on that object.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 01:59:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107427#M22588</guid>
      <dc:creator>mattness</dc:creator>
      <dc:date>2013-10-21T01:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107428#M22589</link>
      <description>&lt;P&gt;Yes, I could do that, but that would only work for that one permutation of customer locations. It doesn't scale to any degree, unless I'm misinterpreting your response.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 02:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107428#M22589</guid>
      <dc:creator>sspencer_splunk</dc:creator>
      <dc:date>2013-10-21T02:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107429#M22590</link>
      <description>&lt;P&gt;Unfortunately Pivot is currently limited by an inability to set up OR operations with its filters. I'll update the Pivot docs to make this clear.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2013 18:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107429#M22590</guid>
      <dc:creator>mattness</dc:creator>
      <dc:date>2013-10-21T18:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107430#M22591</link>
      <description>&lt;P&gt;@ mattness: Where in the documentation did you add that?&lt;BR /&gt;
I'm searching how to use filters with OR, for being able to use checkboxes to drive my dashboard panel (pivot searches)&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 08:40:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107430#M22591</guid>
      <dc:creator>dvb</dc:creator>
      <dc:date>2014-06-12T08:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107431#M22592</link>
      <description>&lt;P&gt;I documented it at the note in the "Configure a filter element" subtopic: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Pivot/UsingthePivotvisualizationeditor#Configure_a_filter_element"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Pivot/UsingthePivotvisualizationeditor#Configure_a_filter_element&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 16:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107431#M22592</guid>
      <dc:creator>mattness</dc:creator>
      <dc:date>2014-06-12T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107432#M22593</link>
      <description>&lt;P&gt;Argh! Please fix this!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 00:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107432#M22593</guid>
      <dc:creator>snoobzilla</dc:creator>
      <dc:date>2015-01-16T00:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107433#M22594</link>
      <description>&lt;P&gt;You sir. Get an upbeat! PLEASE FIX THIS!!&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 22:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107433#M22594</guid>
      <dc:creator>jtrujillo</dc:creator>
      <dc:date>2015-05-15T22:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107434#M22595</link>
      <description>&lt;P&gt;Would have liked to use this also.&lt;BR /&gt;
This is to implement a dashboard with : &lt;BR /&gt;
 - search built with underlying pivot search&lt;BR /&gt;
 - input forms&lt;/P&gt;

&lt;P&gt;being able for the user to give several values as filter like he would do if he was using the search bar  (many choices, the user can type)&lt;/P&gt;

&lt;P&gt;Will try to work around by adding a subfilter afterwards but that's less efficient and transparent.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 16:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107434#M22595</guid>
      <dc:creator>matthieu_araman</dc:creator>
      <dc:date>2015-08-05T16:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107435#M22596</link>
      <description>&lt;P&gt;Learn to use tstats to access the backend gets you OR filtering with tokens against accelerated data. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 19:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107435#M22596</guid>
      <dc:creator>snoobzilla</dc:creator>
      <dc:date>2015-11-04T19:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107436#M22597</link>
      <description>&lt;P&gt;I know this thread is old but since I just had the same question I wanted to post my work around. Basically I added the filter on the base search. I know it may not be practical for all users but it worked for my use case. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 22:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107436#M22597</guid>
      <dc:creator>dasveruckte</dc:creator>
      <dc:date>2016-11-30T22:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Pivot table filter flexibility?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107437#M22598</link>
      <description>&lt;P&gt;I noticed that they have added options to pivot table filters. One that may fit here is "is in the list" which matches to a comma separated list. You can also use contains.&lt;/P&gt;

&lt;P&gt;The option I ended up going with in many cases is learning | tstats syntax then you can do OR.  Inspect a filtered pivot search and look for tstats... then probably change prestats to false, rename node.* as *, and you are off. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 23:21:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pivot-table-filter-flexibility/m-p/107437#M22598</guid>
      <dc:creator>snoobzilla</dc:creator>
      <dc:date>2016-11-30T23:21:51Z</dc:date>
    </item>
  </channel>
</rss>

