<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic display first column against nth column in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/display-first-column-against-nth-column/m-p/644853#M9608</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a log file which looks like below and I want to display in Time against the segment size&lt;BR /&gt;(where first column which is date and the column "SEGSZ" column value against time.)&lt;/P&gt;&lt;P&gt;can anyone help me with a query.&lt;/P&gt;&lt;P&gt;T ID KEY MODE OWNER GROUP CREATOR CGROUP NATTCH &lt;STRONG&gt;SEGSZ&lt;/STRONG&gt; CPID LPID ATIME DTIME CTIME&lt;BR /&gt;28-05-2023 00:00:00 AM;IPC status from &amp;lt;running system&amp;gt; as of Sun May 28 00:00:02 MEST 2023&lt;BR /&gt;m 16779859 0 --rw------- prxm2 tuxedo prxm2 tuxedo 3 &lt;STRONG&gt;1472&lt;/STRONG&gt; 57944 57954 2:12:42 2:12:42 2:12:42&lt;BR /&gt;28-05-2023 00:00:00 AM;Shared Memory:&lt;BR /&gt;m 16779801 0 --rw------- prxm2 tuxedo prxm2 tuxedo 365 156068 57942 60092 4:00:42 4:00:42 2:12:42&lt;BR /&gt;&lt;STRONG&gt;28-05-2023&lt;/STRONG&gt; 00:00:00 AM;m 16779844 0 --rw------- prxm2 tuxedo prxm2 tuxedo 16 &lt;STRONG&gt;4592&lt;/STRONG&gt; 57943 60483 6:00:01 6:00:01 2:12:42&lt;BR /&gt;m 16779771 0 --rw------- prxm2 tuxedo prxm2 tuxedo 3 6152 57940 57950 2:12:42 2:12:42 2:12:42&lt;BR /&gt;&lt;STRONG&gt;28-05-2023&lt;/STRONG&gt; 00:00:00 AM;m 16779786 0 --rw------- prxm2 tuxedo prxm2 tuxedo 3 &lt;STRONG&gt;1472&lt;/STRONG&gt; 57941 57951 2:12:42 2:12:42 2:12:42&lt;BR /&gt;m 16779639 0 --rw------- prxm2 tuxedo prxm2 tuxedo 2 443769 57604 57719 2:12:39 no-entry 2:12:36&lt;BR /&gt;&lt;STRONG&gt;28-05-2023&lt;/STRONG&gt; 00:00:00 AM;m 16779640 0 --rw------- prxm2 tuxedo prxm2 tuxedo 2 &lt;STRONG&gt;1048576&lt;/STRONG&gt; 57604 57719 2:12:39 no-entry 2:12:36&lt;BR /&gt;m 16779465 0 --rw------- prxm2 tuxedo prxm2 tuxedo 2 &lt;STRONG&gt;1048576&lt;/STRONG&gt; 57289 57447 2:12:33 no-entry 2:12:30&lt;/P&gt;</description>
    <pubDate>Sun, 28 May 2023 16:51:55 GMT</pubDate>
    <dc:creator>janhvi23</dc:creator>
    <dc:date>2023-05-28T16:51:55Z</dc:date>
    <item>
      <title>display first column against nth column</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/display-first-column-against-nth-column/m-p/644853#M9608</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a log file which looks like below and I want to display in Time against the segment size&lt;BR /&gt;(where first column which is date and the column "SEGSZ" column value against time.)&lt;/P&gt;&lt;P&gt;can anyone help me with a query.&lt;/P&gt;&lt;P&gt;T ID KEY MODE OWNER GROUP CREATOR CGROUP NATTCH &lt;STRONG&gt;SEGSZ&lt;/STRONG&gt; CPID LPID ATIME DTIME CTIME&lt;BR /&gt;28-05-2023 00:00:00 AM;IPC status from &amp;lt;running system&amp;gt; as of Sun May 28 00:00:02 MEST 2023&lt;BR /&gt;m 16779859 0 --rw------- prxm2 tuxedo prxm2 tuxedo 3 &lt;STRONG&gt;1472&lt;/STRONG&gt; 57944 57954 2:12:42 2:12:42 2:12:42&lt;BR /&gt;28-05-2023 00:00:00 AM;Shared Memory:&lt;BR /&gt;m 16779801 0 --rw------- prxm2 tuxedo prxm2 tuxedo 365 156068 57942 60092 4:00:42 4:00:42 2:12:42&lt;BR /&gt;&lt;STRONG&gt;28-05-2023&lt;/STRONG&gt; 00:00:00 AM;m 16779844 0 --rw------- prxm2 tuxedo prxm2 tuxedo 16 &lt;STRONG&gt;4592&lt;/STRONG&gt; 57943 60483 6:00:01 6:00:01 2:12:42&lt;BR /&gt;m 16779771 0 --rw------- prxm2 tuxedo prxm2 tuxedo 3 6152 57940 57950 2:12:42 2:12:42 2:12:42&lt;BR /&gt;&lt;STRONG&gt;28-05-2023&lt;/STRONG&gt; 00:00:00 AM;m 16779786 0 --rw------- prxm2 tuxedo prxm2 tuxedo 3 &lt;STRONG&gt;1472&lt;/STRONG&gt; 57941 57951 2:12:42 2:12:42 2:12:42&lt;BR /&gt;m 16779639 0 --rw------- prxm2 tuxedo prxm2 tuxedo 2 443769 57604 57719 2:12:39 no-entry 2:12:36&lt;BR /&gt;&lt;STRONG&gt;28-05-2023&lt;/STRONG&gt; 00:00:00 AM;m 16779640 0 --rw------- prxm2 tuxedo prxm2 tuxedo 2 &lt;STRONG&gt;1048576&lt;/STRONG&gt; 57604 57719 2:12:39 no-entry 2:12:36&lt;BR /&gt;m 16779465 0 --rw------- prxm2 tuxedo prxm2 tuxedo 2 &lt;STRONG&gt;1048576&lt;/STRONG&gt; 57289 57447 2:12:33 no-entry 2:12:30&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 16:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/display-first-column-against-nth-column/m-p/644853#M9608</guid>
      <dc:creator>janhvi23</dc:creator>
      <dc:date>2023-05-28T16:51:55Z</dc:date>
    </item>
  </channel>
</rss>

