<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Split Table by Field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525215#M148184</link>
    <description>&lt;P&gt;Greetings...&lt;/P&gt;&lt;P&gt;I have a table that looks like:&lt;BR /&gt;&lt;BR /&gt;Timestamp | Action | User&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail | User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS | Succeed| User2&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail| User2&lt;BR /&gt;&lt;BR /&gt;Is there a way to break this down into separate tables by User such that:&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail | User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;&lt;BR /&gt;YYYY-MM-DD HH:MM:SS | Succeed| User2&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail| User2&lt;/P&gt;</description>
    <pubDate>Sun, 18 Oct 2020 02:00:35 GMT</pubDate>
    <dc:creator>p3hndrx</dc:creator>
    <dc:date>2020-10-18T02:00:35Z</dc:date>
    <item>
      <title>Split Table by Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525215#M148184</link>
      <description>&lt;P&gt;Greetings...&lt;/P&gt;&lt;P&gt;I have a table that looks like:&lt;BR /&gt;&lt;BR /&gt;Timestamp | Action | User&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail | User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS | Succeed| User2&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail| User2&lt;BR /&gt;&lt;BR /&gt;Is there a way to break this down into separate tables by User such that:&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail | User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Succeed| User1&lt;BR /&gt;&lt;BR /&gt;YYYY-MM-DD HH:MM:SS | Succeed| User2&lt;BR /&gt;YYYY-MM-DD HH:MM:SS| Fail| User2&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 02:00:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525215#M148184</guid>
      <dc:creator>p3hndrx</dc:creator>
      <dc:date>2020-10-18T02:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Split Table by Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525216#M148185</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw | eval _raw="Timestamp | Action | User
YYYY-MM-DD HH:MM:SS | Fail | User1
YYYY-MM-DD HH:MM:SS | Succeed | User2
YYYY-MM-DD HH:MM:SS | Succeed | User1
YYYY-MM-DD HH:MM:SS | Succeed | User1
YYYY-MM-DD HH:MM:SS | Fail | User2"
| rename COMMENT as "these are your log sample. from here, the logic"
| rex mode=sed "s/( \| )/,/g"
| multikv forceheader=1
| table Timestamp Action User
| sort User
| autoregress User
| streamstats count as tmp
| eval User=mvdedup(mvappend(User,User_p1))
| fields - User_p1
| mvexpand User
| streamstats count by tmp
| sort User
| foreach * [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;=if(count=2,NULL,'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;')]
| table Timestamp Action User&lt;/LI-CODE&gt;&lt;P&gt;It's not easy to open a line.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 02:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525216#M148185</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-10-18T02:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Split Table by Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525222#M148189</link>
      <description>&lt;P&gt;This gets me pretty close.&lt;/P&gt;&lt;P&gt;I guess there is no trellis for a stats table.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 05:07:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525222#M148189</guid>
      <dc:creator>p3hndrx</dc:creator>
      <dc:date>2020-10-18T05:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Split Table by Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525225#M148191</link>
      <description>&lt;P&gt;That's right, because it wasn't in the request.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 07:09:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-Table-by-Field/m-p/525225#M148191</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-10-18T07:09:48Z</dc:date>
    </item>
  </channel>
</rss>

