<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: query help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480925#M134764</link>
    <description>&lt;P&gt;Thanks a lot for your quick help &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;It worked i just tweaked a little as the interface names vary from device to device. &lt;/P&gt;

&lt;P&gt;| multikv forceheader=1|eval in_metric=metric_name."_in_usage" |eval out_metric=metric_name."_out_usage" | stats values(eval(if(full_metric_name=in_metric,value,null()))) as in_usage values(eval(if(full_metric_name=out_metric,value,null()))) as out_usage by Site Device Interface _time&lt;BR /&gt;
  | table Site Device Interface in_usage out_usage _time&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:23:10 GMT</pubDate>
    <dc:creator>surekhasplunk</dc:creator>
    <dc:date>2020-09-30T04:23:10Z</dc:date>
    <item>
      <title>query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480923#M134762</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;`myquery` | table Site Device Interface metric_name *

returns values like this :

Site    Device  Interface   metric_name full_metric_name    values  _time
Ams-P   xyz123  vni-0/1.0   vni-0/1_0   vni-0/1_0_in_usage  0.72    2020-03-02
Ams-P   xyz123  vni-0/1.0   vni-0/1_0   vni-0/1_0_out_usage 1.61    2020-03-02
Ams-S   xyz678  vni-0/1.0   vni-0/1_0   vni-0/1_0_in_usage  0.62    2020-03-02
Ams-S   xyz678  vni-0/1.0   vni-0/1_0   vni-0/1_0_out_usage 1.20    2020-03-02
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now i want to device the in_usage and out_usage into two different columns and show the output like below :&lt;/P&gt;

&lt;P&gt;Site            Device  Interface   in_usage     out_usage         _time&lt;BR /&gt;
 Ams-P  xyz123  vni-0/1.0   0.72        1.61                     2020-03-02&lt;BR /&gt;
 Ams-S  xyz678  vni-0/1.0   0.62        1.20                     2020-03-02&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480923#M134762</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-09-30T04:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480924#M134763</link>
      <description>&lt;P&gt;@surekhasplunk &lt;/P&gt;

&lt;P&gt;Try this.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;YOUR_SEARCH  | stats values(eval(if(full_metric_name="vni-0/1_0_in_usage",value,null()))) as in_usage values(eval(if(full_metric_name="vni-0/1_0_out_usage",value,null()))) as out_usage by Site Device Interface _time
 | table Site Device Interface in_usage out_usage _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Sample Search&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults | eval _raw=" Site    Device    Interface    metric_name    full_metric_name    value    _time
 Ams-P    xyz123    vni-0/1.0    vni-0/1_0    vni-0/1_0_in_usage    0.72    2020-03-02
 Ams-P    xyz123    vni-0/1.0    vni-0/1_0    vni-0/1_0_out_usage    1.61    2020-03-02
 Ams-S    xyz678    vni-0/1.0    vni-0/1_0    vni-0/1_0_in_usage    0.62    2020-03-02
 Ams-S    xyz678    vni-0/1.0    vni-0/1_0    vni-0/1_0_out_usage    1.20    2020-03-02"
 | multikv forceheader=1
 | stats values(eval(if(full_metric_name="vni-0/1_0_in_usage",value,null()))) as in_usage values(eval(if(full_metric_name="vni-0/1_0_out_usage",value,null()))) as out_usage by Site Device Interface _time
 | table Site Device Interface in_usage out_usage _time
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 02 Mar 2020 06:55:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480924#M134763</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2020-03-02T06:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480925#M134764</link>
      <description>&lt;P&gt;Thanks a lot for your quick help &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;It worked i just tweaked a little as the interface names vary from device to device. &lt;/P&gt;

&lt;P&gt;| multikv forceheader=1|eval in_metric=metric_name."_in_usage" |eval out_metric=metric_name."_out_usage" | stats values(eval(if(full_metric_name=in_metric,value,null()))) as in_usage values(eval(if(full_metric_name=out_metric,value,null()))) as out_usage by Site Device Interface _time&lt;BR /&gt;
  | table Site Device Interface in_usage out_usage _time&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/query-help/m-p/480925#M134764</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-09-30T04:23:10Z</dc:date>
    </item>
  </channel>
</rss>

