<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help using array data on a dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349109#M22741</link>
    <description>&lt;P&gt;Would like to add a small feature, but sorry to bug you. &lt;/P&gt;

&lt;P&gt;Instead of DATA COLUMN in the table , can we have the report to look like something below which will just highlight the holidays in the application calendar&lt;/P&gt;

&lt;P&gt;App 1 Holidays  App 2 Holidays  App 3 Holidays  App 4 Holidays  App 5 Holidays&lt;BR /&gt;
Date1   Date1   Date1   Date1   Date1&lt;BR /&gt;
Date2   Date2                Date2  Date2&lt;BR /&gt;
            Date3   Date3&lt;BR /&gt;&lt;BR /&gt;
Date4   Date4   Date4   Date4   Date4&lt;BR /&gt;
Date5   Date5   Date5   Date5   Date5&lt;BR /&gt;
Date6   Date6   Date6   Date6   Date6&lt;BR /&gt;
Date7   Date7   Date7   Date7   Date7&lt;BR /&gt;
Date8   Date8   Date8   Date8   Date8&lt;BR /&gt;
Date9   Date9   Date9   Date9   Date9&lt;BR /&gt;
Date10  Date10  Date10  Date10  Date10&lt;BR /&gt;
Date11  Date11  Date11  Date11  Date11&lt;/P&gt;</description>
    <pubDate>Thu, 21 Dec 2017 05:19:00 GMT</pubDate>
    <dc:creator>madakkas</dc:creator>
    <dc:date>2017-12-21T05:19:00Z</dc:date>
    <item>
      <title>Need help using array data on a dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349106#M22738</link>
      <description>&lt;P&gt;Below is the raw data that we have and enters Splunk &lt;BR /&gt;
Raw Data and each of the application holidays enters as a single record for each date for each application with a unique source type&lt;/P&gt;

&lt;P&gt;Raw Data&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;App 1 Holidays  App 2 Holidays  App 3 Holidays  App 4 Holidays  App 5 Holidays
Date1   Date1   Date1   Date1   Date1
Date2   Date2   Date3   Date2   Date2
Date4   Date3   Date4   Date4   Date4
Date5   Date4   Date5   Date5   Date5
Date6   Date5   Date6   Date6   Date6
Date7   Date6   Date7   Date7   Date7
Date8   Date7   Date8   Date8   Date8
Date9   Date8   Date9   Date9   Date9
Date10  Date9   Date10  Date10  Date10
Date11  Date10  Date11  Date11  Date11
    Date11  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Am trying to build a dashboard wherein it compares all the holidays and gets a list of matched and unmatched holidays. Expectations as below &lt;BR /&gt;
Part I - &lt;BR /&gt;
Matched Holidays&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Holidays    Application 1   Application 2   Application 3   Application 4   Application 5
Date1   Matched Matched Matched Matched Matched
Date4   Matched Matched Matched Matched Matched
Date5   Matched Matched Matched Matched Matched
Date6   Matched Matched Matched Matched Matched
Date7   Matched Matched Matched Matched Matched
Date8   Matched Matched Matched Matched Matched
Date9   Matched Matched Matched Matched Matched
Date10  Matched Matched Matched Matched Matched
Date11  Matched Matched Matched Matched Matched
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Part II&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Un Matched Holidays
Holidays    Application 1   Application 2   Application 3   Application 4   Application 5
Date2   Matched Matched No Match    Matched Matched
Date3   No Match    Matched Matched No Match    No Match
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I was able to do the needed to create the report for matching holidays(Part I ) but was unable to manage the unmatched holidays.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MFSOURCETYPE=*_HOLIDAY  |replace "DATA" with "" in DATA as DATA | table DATA MFSOURCETYPE | stats COUNT as COUNT by DATA | table DATA COUNT |
eval app1 = if(COUNT = "3" ,"Match", "No Match") |  eval app2 = if(COUNT = "3" ,"Match", "No Match") | eval app3 = if(COUNT = "3" ,"Match", "No Match") |
table DATA app1 app2 app3 | where app1 = "Match"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sample JSON Data as below&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{ [-] 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DATA: DATE1 , &lt;BR /&gt;
   MFSOURCETYPE: App1_HOLIDAY &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;}
{ [-] 
   DATA: DATE2 , 
   MFSOURCETYPE: App1_HOLIDAY 
}
{ [-] 
   DATA: DATE1, 
   MFSOURCETYPE: APP2_HOLIDAY 
}   
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;NOTE – Date Format – “DD-MM-YYYY”&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 10:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349106#M22738</guid>
      <dc:creator>madakkas</dc:creator>
      <dc:date>2017-12-19T10:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Need help using array data on a dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349107#M22739</link>
      <description>&lt;P&gt;Give this a try&lt;BR /&gt;
Part I - Matched Holidays&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; MFSOURCETYPE=*_HOLIDAY  |replace "DATA" with "" in DATA as DATA 
| table DATA MFSOURCETYPE | dedup DATA MFSOURCETYPE 
| chart count over DATA by MFSOURCETYPE 
| foreach * [eval "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=case('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=0,"No Match", '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=1,"Matched",true(),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;') ]
| eval keep="Y" 
| foreach * [eval keep=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'="No Match","N",keep)]
| where keep="Y" | fields - keep
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Part II - Un Matched Holidays&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; MFSOURCETYPE=*_HOLIDAY  |replace "DATA" with "" in DATA as DATA 
| table DATA MFSOURCETYPE | dedup DATA MFSOURCETYPE 
| chart count over DATA by MFSOURCETYPE 
| foreach * [eval "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=case('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=0,"No Match", '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=1,"Matched",true(),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;') ]
| eval keep="Y" 
| foreach * [eval keep=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'="No Match","N",keep)]
| where keep="N" | fields - keep
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 Dec 2017 17:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349107#M22739</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-12-19T17:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need help using array data on a dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349108#M22740</link>
      <description>&lt;P&gt;Just to the point and very perfect. Many Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 03:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349108#M22740</guid>
      <dc:creator>madakkas</dc:creator>
      <dc:date>2017-12-20T03:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need help using array data on a dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349109#M22741</link>
      <description>&lt;P&gt;Would like to add a small feature, but sorry to bug you. &lt;/P&gt;

&lt;P&gt;Instead of DATA COLUMN in the table , can we have the report to look like something below which will just highlight the holidays in the application calendar&lt;/P&gt;

&lt;P&gt;App 1 Holidays  App 2 Holidays  App 3 Holidays  App 4 Holidays  App 5 Holidays&lt;BR /&gt;
Date1   Date1   Date1   Date1   Date1&lt;BR /&gt;
Date2   Date2                Date2  Date2&lt;BR /&gt;
            Date3   Date3&lt;BR /&gt;&lt;BR /&gt;
Date4   Date4   Date4   Date4   Date4&lt;BR /&gt;
Date5   Date5   Date5   Date5   Date5&lt;BR /&gt;
Date6   Date6   Date6   Date6   Date6&lt;BR /&gt;
Date7   Date7   Date7   Date7   Date7&lt;BR /&gt;
Date8   Date8   Date8   Date8   Date8&lt;BR /&gt;
Date9   Date9   Date9   Date9   Date9&lt;BR /&gt;
Date10  Date10  Date10  Date10  Date10&lt;BR /&gt;
Date11  Date11  Date11  Date11  Date11&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 05:19:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Need-help-using-array-data-on-a-dashboard/m-p/349109#M22741</guid>
      <dc:creator>madakkas</dc:creator>
      <dc:date>2017-12-21T05:19:00Z</dc:date>
    </item>
  </channel>
</rss>

