<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: table and lookup in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552535#M38266</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232048"&gt;@simo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try this .&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH 
| table name value 
| search 
    [| inputlookup YOUR_LOOKUP 
    | table value ] 
| chart count over name by value&lt;/LI-CODE&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 21 May 2021 08:41:38 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2021-05-21T08:41:38Z</dc:date>
    <item>
      <title>table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552532#M38264</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;i have the following situation&lt;BR /&gt;a lookup&amp;nbsp;with the following values&lt;/P&gt;&lt;TABLE border="0" width="64" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="21"&gt;value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="21"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a table with name and value&lt;/P&gt;&lt;TABLE border="0" width="128" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="21"&gt;name&lt;/TD&gt;&lt;TD width="64"&gt;value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;a&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;b&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="21"&gt;a&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;b&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;b&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;a&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="21"&gt;b&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to be able to view a table as follows on a dashboard.&amp;nbsp;must count how many times there is one of the values ​​in lookup for the name&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE border="0" width="256" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="21"&gt;name&lt;/TD&gt;&lt;TD width="64"&gt;1&lt;/TD&gt;&lt;TD width="64"&gt;2&lt;/TD&gt;&lt;TD width="64"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;a&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;b&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="21"&gt;c&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I add the value 4 in the lookup the table automatically becomes&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE border="0" width="320" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="21"&gt;name&lt;/TD&gt;&lt;TD width="64"&gt;1&lt;/TD&gt;&lt;TD width="64"&gt;2&lt;/TD&gt;&lt;TD width="64"&gt;3&lt;/TD&gt;&lt;TD width="64"&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;a&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;b&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="21"&gt;c&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for any help&lt;/P&gt;&lt;P&gt;Simone&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 08:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552532#M38264</guid>
      <dc:creator>simo</dc:creator>
      <dc:date>2021-05-21T08:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552535#M38266</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232048"&gt;@simo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try this .&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH 
| table name value 
| search 
    [| inputlookup YOUR_LOOKUP 
    | table value ] 
| chart count over name by value&lt;/LI-CODE&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 08:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552535#M38266</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-05-21T08:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552538#M38268</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="name	value
a	1
b	2
a	1
b	2
b	2
a	2
b	1"
| multikv forceheader=1
| fields - _* linecount
| stats count by name value
| append
    [| makeresults
    | eval value=split("1234","")
    | mvexpand value
    | eval count=0
    | eval name=""
    | table name value count]
| xyseries name value count
| fillnull value=0
| where name!=""&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 21 May 2021 08:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/552538#M38268</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-21T08:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553080#M38344</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the reply,&amp;nbsp;but it doesn't seem to work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;if I add a value b 5&lt;/P&gt;&lt;P&gt;| makeresults&lt;BR /&gt;| eval _raw="name value&lt;BR /&gt;a 1&lt;BR /&gt;b 2&lt;BR /&gt;a 1&lt;BR /&gt;b 2&lt;BR /&gt;b 2&lt;BR /&gt;a 2&lt;BR /&gt;b 1&lt;BR /&gt;b 5"&lt;BR /&gt;| multikv forceheader=1&lt;BR /&gt;| fields - _* linecount&lt;BR /&gt;| stats count by name value&lt;BR /&gt;| append&lt;BR /&gt;[| makeresults&lt;BR /&gt;| eval value=split("1234","")&lt;BR /&gt;| mvexpand value&lt;BR /&gt;| eval count=0&lt;BR /&gt;| eval name=""&lt;BR /&gt;| table name value count]&lt;BR /&gt;| xyseries name value count&lt;BR /&gt;| fillnull value=0&lt;BR /&gt;| where name!=""&lt;/P&gt;&lt;P&gt;a new column with the value is added 5,&amp;nbsp;but this must not happen because there must be only the columns in the lookup.&lt;/P&gt;&lt;P&gt;Simone&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 07:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553080#M38344</guid>
      <dc:creator>simo</dc:creator>
      <dc:date>2021-05-26T07:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553081#M38345</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232048"&gt;@simo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you think to use transponse command?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose&lt;/A&gt;&lt;/P&gt;&lt;P&gt;search example&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your search | table Name Value | transpose  header_field=Value column_name=Field_name&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 07:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553081#M38345</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-26T07:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553086#M38348</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="name,value
a,1
b,2
a,1
b,2
b,2
a,2
b,1
b,5"
| multikv forceheader=1
| fields - _* linecount
| stats count by name value
| append
[| makeresults
| eval value=split("1234","")
| mvexpand value
| eval keep="keep"
| eval count=0
| eval name=""
| table name value count keep]
| eventstats values(keep) as keep by value
| where keep="keep"
| xyseries name value count
| fillnull value=0
| where name!=""&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 May 2021 08:21:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553086#M38348</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-26T08:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553120#M38361</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ok so it goes,&amp;nbsp;but if I have to add another field for example&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;name&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;surname&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;mario&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;rossi&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;marco&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;ferrari&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;mario&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;russo&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;marco&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;ferrari&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;marco&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;ferrari&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;always assuming the values ​​from 1 to 4,&amp;nbsp;it's possible?&lt;/P&gt;&lt;P&gt;Simone&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 11:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553120#M38361</guid>
      <dc:creator>simo</dc:creator>
      <dc:date>2021-05-26T11:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: table and lookup</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553121#M38362</link>
      <description>&lt;P&gt;You would have to concatenate name and surname with a suitable delimiter into a single field before the xyseries, then split the field back into name and surname using the delimiter to separate them.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 11:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/table-and-lookup/m-p/553121#M38362</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-26T11:05:27Z</dc:date>
    </item>
  </channel>
</rss>

