<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Need Help]how to put columns for one DataCenter together in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523621#M147691</link>
    <description>&lt;LI-CODE lang="markup"&gt;sourcetype=xxxx AND "POST /123?123_form_type=review&amp;amp;itrModule=cherie*"
| rex field=_raw "POST\s+(?&amp;lt;uri&amp;gt;.*)HTTP.*name\=(?&amp;lt;name&amp;gt;.*?)\&amp;amp;"
| eval saveMode=if(uri like "%cherie=true%", "1", "0")
| bin span=1d _time
| stats count(eval(saveMode=1)) as autosave
count(eval(saveMode=0 OR saveMode=1)) as total by _time DC
| eval percent=round(autosave * 100 / total,2)
| chart values(total) as total values(autosave) as autosave values(percent) as percent by _time DC
| transpose 0
| rex field=column mode=sed "s/(?&amp;lt;max&amp;gt;autosave): (?&amp;lt;cert&amp;gt;.+)/\2: field1/"
| rex field=column mode=sed "s/(?&amp;lt;tot&amp;gt;total): (?&amp;lt;cert&amp;gt;.+)/\2: field2/"
| rex field=column mode=sed "s/(?&amp;lt;perc&amp;gt;percent): (?&amp;lt;cert&amp;gt;.+)/\2: field3/"
| transpose 0 header_field=column
| fields - column
| table _time *
| transpose 0
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f1&amp;gt;field1)/autosave: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f2&amp;gt;field2)/total: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f3&amp;gt;field3)/autosave%: \1/"
| transpose 0 header_field=column
| fields - column&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 08 Oct 2020 08:41:43 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2020-10-08T08:41:43Z</dc:date>
    <item>
      <title>[Need Help]how to put columns for one DataCenter together</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523593#M147678</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I have below query:&lt;/P&gt;&lt;P&gt;sourcetype=xxxx AND "POST /123?123_form_type=review&amp;amp;itrModule=cherie*"&lt;BR /&gt;| rex field=_raw "POST\s+(?&amp;lt;uri&amp;gt;.*)HTTP.*name\=(?&amp;lt;name&amp;gt;.*?)\&amp;amp;"&lt;BR /&gt;| eval saveMode=if(uri like "%cherie=true%", "1", "0")&lt;BR /&gt;| timechart span=1d count(eval(saveMode=1)) as autosave&lt;BR /&gt;count(eval(saveMode=0 OR saveMode=1)) as total by DC&lt;/P&gt;&lt;P&gt;Query result in splunk:&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;TABLE border="1" width="76.54838709677419%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;_time&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;autosave: DC23&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;autosave: DC41&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;autosave: DC44&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;total: DC23&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;total: DC41&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;total: DC44&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;2020-10-07&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;247&lt;/P&gt;&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;50&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;87&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;500&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;600&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;700&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;2020-10-08&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;304&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;12&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;500&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;600&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;700&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;But&amp;nbsp; the expected result&amp;nbsp; I want is:&lt;/P&gt;&lt;P&gt;1. put the columns with same DC together for easy to compare&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. add a new column autosave%: DCxx which is calculated out by autosave/total*100, I tried with eval command after timechart command, but the column doesn't display.&lt;/P&gt;&lt;P&gt;| timechart span=1d count(eval(saveMode=1)) as autosave&lt;BR /&gt;count(eval(saveMode=0 OR saveMode=1)) as total by DC&lt;BR /&gt;| eval autosave%=round((autosave/total) * 100, 2)&lt;/P&gt;&lt;P&gt;So the expected table returned should be like this. Is this achievable?&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%"&gt;_time&lt;/TD&gt;&lt;TD width="10%"&gt;autosave: DC23&lt;/TD&gt;&lt;TD width="10%"&gt;total: DC23&lt;/TD&gt;&lt;TD width="10%"&gt;autosave%: DC23&lt;/TD&gt;&lt;TD width="10%"&gt;autosave: DC41&lt;/TD&gt;&lt;TD width="10%"&gt;total: DC41&lt;/TD&gt;&lt;TD width="10%"&gt;autosave%: DC41&lt;/TD&gt;&lt;TD width="10%"&gt;autosave: DC44&lt;/TD&gt;&lt;TD width="10%"&gt;total: DC44&lt;/TD&gt;&lt;TD width="10%"&gt;autosave%: DC44&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%"&gt;2020-10-07&lt;/TD&gt;&lt;TD width="10%"&gt;247&lt;/TD&gt;&lt;TD width="10%"&gt;500&lt;/TD&gt;&lt;TD width="10%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="10%"&gt;50&lt;/TD&gt;&lt;TD width="10%"&gt;600&lt;/TD&gt;&lt;TD width="10%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="10%"&gt;87&lt;/TD&gt;&lt;TD width="10%"&gt;700&lt;/TD&gt;&lt;TD width="10%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%"&gt;2020-10-08&lt;/TD&gt;&lt;TD width="10%"&gt;304&lt;/TD&gt;&lt;TD width="10%"&gt;500&lt;/TD&gt;&lt;TD width="10%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="10%"&gt;0&lt;/TD&gt;&lt;TD width="10%"&gt;600&lt;/TD&gt;&lt;TD width="10%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="10%"&gt;12&lt;/TD&gt;&lt;TD width="10%"&gt;700&lt;/TD&gt;&lt;TD width="10%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Cherie&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 07:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523593#M147678</guid>
      <dc:creator>cheriemilk</dc:creator>
      <dc:date>2020-10-08T07:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: [Need Help]how to put columns for one DataCenter together</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523621#M147691</link>
      <description>&lt;LI-CODE lang="markup"&gt;sourcetype=xxxx AND "POST /123?123_form_type=review&amp;amp;itrModule=cherie*"
| rex field=_raw "POST\s+(?&amp;lt;uri&amp;gt;.*)HTTP.*name\=(?&amp;lt;name&amp;gt;.*?)\&amp;amp;"
| eval saveMode=if(uri like "%cherie=true%", "1", "0")
| bin span=1d _time
| stats count(eval(saveMode=1)) as autosave
count(eval(saveMode=0 OR saveMode=1)) as total by _time DC
| eval percent=round(autosave * 100 / total,2)
| chart values(total) as total values(autosave) as autosave values(percent) as percent by _time DC
| transpose 0
| rex field=column mode=sed "s/(?&amp;lt;max&amp;gt;autosave): (?&amp;lt;cert&amp;gt;.+)/\2: field1/"
| rex field=column mode=sed "s/(?&amp;lt;tot&amp;gt;total): (?&amp;lt;cert&amp;gt;.+)/\2: field2/"
| rex field=column mode=sed "s/(?&amp;lt;perc&amp;gt;percent): (?&amp;lt;cert&amp;gt;.+)/\2: field3/"
| transpose 0 header_field=column
| fields - column
| table _time *
| transpose 0
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f1&amp;gt;field1)/autosave: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f2&amp;gt;field2)/total: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f3&amp;gt;field3)/autosave%: \1/"
| transpose 0 header_field=column
| fields - column&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 08 Oct 2020 08:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523621#M147691</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-08T08:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: [Need Help]how to put columns for one DataCenter together</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523702#M147727</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the help. I tried your solution and it does return the expected table format now.&lt;/P&gt;&lt;P&gt;I can understand below part.&lt;/P&gt;&lt;PRE&gt;sourcetype=xxxx AND "POST /123?123_form_type=review&amp;amp;itrModule=cherie*"
| rex field=_raw "POST\s+(?&amp;lt;uri&amp;gt;.*)HTTP.*name\=(?&amp;lt;name&amp;gt;.*?)\&amp;amp;"
| eval saveMode=if(uri like "%cherie=true%", "1", "0")
| bin span=1d _time
| stats count(eval(saveMode=1)) as autosave
count(eval(saveMode=0 OR saveMode=1)) as total by _time DC
| eval percent=round(autosave * 100 / total,2)
| chart values(total) as total values(autosave) as autosave values(percent) as percent by _time DC&lt;/PRE&gt;&lt;P&gt;But for the rest part It's a bit complex for me to understand. Could you please help explain the solution logic that has 3 times of transpose and 6 rex commands with mode=sed.&lt;/P&gt;&lt;PRE&gt;| transpose 0
| rex field=column mode=sed "s/(?&amp;lt;max&amp;gt;autosave): (?&amp;lt;cert&amp;gt;.+)/\2: field1/"
| rex field=column mode=sed "s/(?&amp;lt;tot&amp;gt;total): (?&amp;lt;cert&amp;gt;.+)/\2: field2/"
| rex field=column mode=sed "s/(?&amp;lt;perc&amp;gt;percent): (?&amp;lt;cert&amp;gt;.+)/\2: field3/"
| transpose 0 header_field=column
| fields - column
| table _time *
| transpose 0
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f1&amp;gt;field1)/autosave: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f2&amp;gt;field2)/total: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f3&amp;gt;field3)/autosave%: \1/"
| transpose 0 header_field=column
| fields - column&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Cherie&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 13:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523702#M147727</guid>
      <dc:creator>cheriemilk</dc:creator>
      <dc:date>2020-10-08T13:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: [Need Help]how to put columns for one DataCenter together</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523706#M147729</link>
      <description>&lt;LI-CODE lang="markup"&gt;/* Transpose to get the field names as values in the column field */
| transpose 0
/* Rename the fields so that they can be ordered in the order required */
| rex field=column mode=sed "s/(?&amp;lt;max&amp;gt;autosave): (?&amp;lt;cert&amp;gt;.+)/\2: field1/"
| rex field=column mode=sed "s/(?&amp;lt;tot&amp;gt;total): (?&amp;lt;cert&amp;gt;.+)/\2: field2/"
| rex field=column mode=sed "s/(?&amp;lt;perc&amp;gt;percent): (?&amp;lt;cert&amp;gt;.+)/\2: field3/"
/* Transpose using the values in the column field as field names in transposed table */
| transpose 0 header_field=column
/* Remove column field (as it isn't needed) */
| fields - column
/* Reorder the fields in the table */
| table _time *
/* Transpose so we can rename the fields back */
| transpose 0
/* Rename the values in the column field */
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f1&amp;gt;field1)/autosave: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f2&amp;gt;field2)/total: \1/"
| rex field=column mode=sed "s/(?&amp;lt;cert&amp;gt;.+): (?&amp;lt;f3&amp;gt;field3)/autosave%: \1/"
/* Transpose using the values in the column field as field names in transposed table */
| transpose 0 header_field=column
/* Remove column field (as it isn't needed) */
| fields - column&lt;/LI-CODE&gt;&lt;P&gt;Hope that helps with your understanding&lt;/P&gt;&lt;P&gt;If you want to understand more, try just adding the commands one at a time and see what each is doing to the results.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 14:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-how-to-put-columns-for-one-DataCenter-together/m-p/523706#M147729</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-08T14:14:30Z</dc:date>
    </item>
  </channel>
</rss>

