<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you add a blank row after each unique host in search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403646#M116789</link>
    <description>&lt;P&gt;Any methods to compare string values of two different rows with something like an if -else statement?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2019 09:07:48 GMT</pubDate>
    <dc:creator>kenntun</dc:creator>
    <dc:date>2019-01-14T09:07:48Z</dc:date>
    <item>
      <title>How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403641#M116784</link>
      <description>&lt;P&gt;I have a search statement in a customized dashboard to show the disk utilization of my servers. I would like to add a blank row after each unique server, such as follows:&lt;/P&gt;

&lt;P&gt;Current:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host          mount     Disk size(GB)    Free(GB)   
host1        /            5.0           3.0 
host1        /etc          5.0           2.4
host2        /             10.0         4.0 
host2        /etc          20.0        14.0
host2        /var          15.0        8.9
host3        /            15.0        6.0 
host3        /mnt         15.0        10.3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What I wanted:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host          mount     Disk size(GB)    Free(GB)   
host1        /            5.0           3.0 
host1        /etc          5.0           2.4

host2        /             10.0         4.0 
host2        /etc          20.0        14.0
host2        /var          15.0        8.9

host3        /            15.0        6.0 
host3        /mnt         15.0        10.3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note: Not all servers have the same number of mounts.&lt;/P&gt;

&lt;P&gt;My search statement:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats latest(JFS.storage) AS storage, latest(JFS.storage_free) AS storage_free, latest(JFS.storage_used) AS storage_used, latest(JFS.storage_used_percent) AS storage_used_percent from datamodel=NMON_Data_JFS
where (nodename = JFS.DF_STORAGE) (host=$host-prefilter$) ($frameID$) ($osfilter$) ($host$) ($mount$) (JFS.mount=$fsfilter$) groupby host JFS.mount prestats=true
| stats dedup_splitvals=t latest(JFS.storage) AS storage, latest(JFS.storage_free) AS storage_free, latest(JFS.storage_used) AS storage_used, latest(JFS.storage_used_percent) AS storage_used_percent by host JFS.mount
| sort limit=0 host
| rename "JFS.mount" AS "mount"
| fields host, mount, storage, storage_free,storage_used,storage_used_percent
| foreach storage storage_free storage_used [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = round(('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'$df_storage_unit_math$), 2) ]
| rename storage as "Disk Size ($df_storage_unit_legend$)", storage_free as "Free ($df_storage_unit_legend$)", storage_used as "Used ($df_storage_unit_legend$)", storage_used_percent as "Used (%)"
| eval UsedPct=if(isnum('Used (%)'), 'Used (%)', 0 )
| fields host, mount, "Disk Size ($df_storage_unit_legend$)", "Free ($df_storage_unit_legend$)", "Used ($df_storage_unit_legend$)", "Used (%)"
| eval "Used (%)" = if(isnull('storage used (%)'), (('Used ($df_storage_unit_legend$)'/'Disk Size ($df_storage_unit_legend$)')*100), 'Used (%)')
| foreach storage*%* [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = round('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;', 2) ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 14 Jan 2019 04:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403641#M116784</guid>
      <dc:creator>kenntun</dc:creator>
      <dc:date>2019-01-14T04:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403642#M116785</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Please look.... this may be of some use &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/399417/add-a-blank-row-in-the-table.html"&gt;https://answers.splunk.com/answers/399417/add-a-blank-row-in-the-table.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 05:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403642#M116785</guid>
      <dc:creator>shrikantgulia1</dc:creator>
      <dc:date>2019-01-14T05:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403643#M116786</link>
      <description>&lt;P&gt;you can also use fillnull&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 05:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403643#M116786</guid>
      <dc:creator>shrikantgulia1</dc:creator>
      <dc:date>2019-01-14T05:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403644#M116787</link>
      <description>&lt;P&gt;Could you elaborate more? Thanks a lot&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 05:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403644#M116787</guid>
      <dc:creator>kenntun</dc:creator>
      <dc:date>2019-01-14T05:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403645#M116788</link>
      <description>&lt;P&gt;Thanks for your help.&lt;BR /&gt;
However, the situation is a bit different since the post only have to add one line in the second row, but I want to add a single line every time the value of the first column is different. Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 08:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403645#M116788</guid>
      <dc:creator>kenntun</dc:creator>
      <dc:date>2019-01-14T08:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403646#M116789</link>
      <description>&lt;P&gt;Any methods to compare string values of two different rows with something like an if -else statement?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403646#M116789</guid>
      <dc:creator>kenntun</dc:creator>
      <dc:date>2019-01-14T09:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403647#M116790</link>
      <description>&lt;P&gt;fillnull value="as" test,&lt;/P&gt;

&lt;P&gt;this is used when you dont have any vale in a field and you give it a value&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403647#M116790</guid>
      <dc:creator>shrikantgulia1</dc:creator>
      <dc:date>2019-01-14T09:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403648#M116791</link>
      <description>&lt;P&gt;I think you misunderstood my situation. There are no blank fields in my search results.&lt;BR /&gt;
I've edited the question. Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403648#M116791</guid>
      <dc:creator>kenntun</dc:creator>
      <dc:date>2019-01-14T09:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do you add a blank row after each unique host in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403649#M116792</link>
      <description>&lt;P&gt;Hi @kenntun ,&lt;/P&gt;

&lt;P&gt;I have used above data as input and loaded it into Splunk. Below is one possible solution.  I hope this solution can help you. &lt;BR /&gt;
&lt;STRONG&gt;P.S.:&lt;/STRONG&gt;  I have used sorting on the basis of &lt;STRONG&gt;hostname&lt;/STRONG&gt; and &lt;STRONG&gt;mount&lt;/STRONG&gt; and accordingly. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
 | eval data="host1,x, , ;host2,x, , ;host3,x, , " 
 | makemv data delim=";" 
 | mvexpand data 
 | makemv data delim="," 
| eval hostval=mvindex(data,0),mount=mvindex(data,1),Disksize=mvindex(data,2),Free=mvindex(data,3)
| table hostval,mount,Disksize,Free
| append
    [search index=test source="C:\\Splunk_Data\\Test\\testdata_splunk.csv"
| dedup hostval,mount
| table hostval,mount,Disksize,Free
]
| sort hostval,mount
| eval hostval=if(mount="x","",hostval),mount=if(mount="x"," ",mount)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 14 Jan 2019 10:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-add-a-blank-row-after-each-unique-host-in-search/m-p/403649#M116792</guid>
      <dc:creator>askkawalkar</dc:creator>
      <dc:date>2019-01-14T10:52:45Z</dc:date>
    </item>
  </channel>
</rss>

