<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create new columns from results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-new-columns-from-results/m-p/622126#M216249</link>
    <description>&lt;P class=""&gt;I'm trying to create table with the top 5 results split into columns, so that I can have multiple results per line, grouped by date. Here's what I have:&lt;/P&gt;
&lt;P class=""&gt;|union&lt;BR /&gt;[search index=Firewall BlockFromBadActor| top src_ip by Date limit=5 | rename count as IPCount]&lt;BR /&gt;[search index=Firewall BlockFromBadActor| top dest_port by Date limit=5 | rename count as PortCount]&lt;BR /&gt;| stats values(*) as * by Date&lt;BR /&gt;| fields Date,src_ip,IPCount,dest_port,PortCount&lt;/P&gt;
&lt;P&gt;Date src_ip IPCount dest_port PortCount&lt;/P&gt;
&lt;TABLE width="337px"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="103px"&gt;2022/11/25&lt;/TD&gt;
&lt;TD width="59px"&gt;&lt;A class="" href="https://1.1.1.1/" target="_blank" rel="noopener nofollow ugc"&gt;1.1.1.1&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://2.2.2.2/" target="_blank" rel="noopener nofollow ugc"&gt;2.2.2.2&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://3.3.3.3/" target="_blank" rel="noopener nofollow ugc"&gt;3.3.3.3&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://4.4.4.4/" target="_blank" rel="noopener nofollow ugc"&gt;4.4.4.4&lt;/A&gt;&lt;BR /&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="51px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;TD width="61px"&gt;1&lt;BR /&gt;2&lt;BR /&gt;3&lt;BR /&gt;4&lt;BR /&gt;5&lt;/TD&gt;
&lt;TD width="63px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="103px"&gt;2022/11/24&lt;/TD&gt;
&lt;TD width="59px"&gt;&lt;A class="" href="https://1.1.1.1/" target="_blank" rel="noopener nofollow ugc"&gt;1.1.1.1&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://2.2.2.2/" target="_blank" rel="noopener nofollow ugc"&gt;2.2.2.2&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://3.3.3.3/" target="_blank" rel="noopener nofollow ugc"&gt;3.3.3.3&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://4.4.4.4/" target="_blank" rel="noopener nofollow ugc"&gt;4.4.4.4&lt;/A&gt;&lt;BR /&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="51px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;TD width="61px"&gt;1&lt;BR /&gt;2&lt;BR /&gt;3&lt;BR /&gt;4&lt;BR /&gt;5&lt;/TD&gt;
&lt;TD width="63px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;What I'm trying to get&lt;/P&gt;
&lt;P&gt;Date IP 1 IP1 Count IP 2 IP 2 Count Port 1 Port 1 Count Port 2 Port 2 Count&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2022/11/25&lt;/TD&gt;
&lt;TD&gt;1.1.1.1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2.2.2.2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022/11/24&lt;/TD&gt;
&lt;TD&gt;1.1.1.1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2.2.2.2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class=""&gt;I cannot seem to find any way to make the individual query results into new columns.&lt;/P&gt;</description>
    <pubDate>Sun, 27 Nov 2022 16:06:08 GMT</pubDate>
    <dc:creator>CyberMage</dc:creator>
    <dc:date>2022-11-27T16:06:08Z</dc:date>
    <item>
      <title>How to create new columns from results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-new-columns-from-results/m-p/622126#M216249</link>
      <description>&lt;P class=""&gt;I'm trying to create table with the top 5 results split into columns, so that I can have multiple results per line, grouped by date. Here's what I have:&lt;/P&gt;
&lt;P class=""&gt;|union&lt;BR /&gt;[search index=Firewall BlockFromBadActor| top src_ip by Date limit=5 | rename count as IPCount]&lt;BR /&gt;[search index=Firewall BlockFromBadActor| top dest_port by Date limit=5 | rename count as PortCount]&lt;BR /&gt;| stats values(*) as * by Date&lt;BR /&gt;| fields Date,src_ip,IPCount,dest_port,PortCount&lt;/P&gt;
&lt;P&gt;Date src_ip IPCount dest_port PortCount&lt;/P&gt;
&lt;TABLE width="337px"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="103px"&gt;2022/11/25&lt;/TD&gt;
&lt;TD width="59px"&gt;&lt;A class="" href="https://1.1.1.1/" target="_blank" rel="noopener nofollow ugc"&gt;1.1.1.1&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://2.2.2.2/" target="_blank" rel="noopener nofollow ugc"&gt;2.2.2.2&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://3.3.3.3/" target="_blank" rel="noopener nofollow ugc"&gt;3.3.3.3&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://4.4.4.4/" target="_blank" rel="noopener nofollow ugc"&gt;4.4.4.4&lt;/A&gt;&lt;BR /&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="51px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;TD width="61px"&gt;1&lt;BR /&gt;2&lt;BR /&gt;3&lt;BR /&gt;4&lt;BR /&gt;5&lt;/TD&gt;
&lt;TD width="63px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="103px"&gt;2022/11/24&lt;/TD&gt;
&lt;TD width="59px"&gt;&lt;A class="" href="https://1.1.1.1/" target="_blank" rel="noopener nofollow ugc"&gt;1.1.1.1&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://2.2.2.2/" target="_blank" rel="noopener nofollow ugc"&gt;2.2.2.2&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://3.3.3.3/" target="_blank" rel="noopener nofollow ugc"&gt;3.3.3.3&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://4.4.4.4/" target="_blank" rel="noopener nofollow ugc"&gt;4.4.4.4&lt;/A&gt;&lt;BR /&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="51px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;TD width="61px"&gt;1&lt;BR /&gt;2&lt;BR /&gt;3&lt;BR /&gt;4&lt;BR /&gt;5&lt;/TD&gt;
&lt;TD width="63px"&gt;5000&lt;BR /&gt;4000&lt;BR /&gt;3000&lt;BR /&gt;2000&lt;BR /&gt;1000&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;What I'm trying to get&lt;/P&gt;
&lt;P&gt;Date IP 1 IP1 Count IP 2 IP 2 Count Port 1 Port 1 Count Port 2 Port 2 Count&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2022/11/25&lt;/TD&gt;
&lt;TD&gt;1.1.1.1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2.2.2.2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2022/11/24&lt;/TD&gt;
&lt;TD&gt;1.1.1.1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2.2.2.2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;5000&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;4000&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class=""&gt;I cannot seem to find any way to make the individual query results into new columns.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 16:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-new-columns-from-results/m-p/622126#M216249</guid>
      <dc:creator>CyberMage</dc:creator>
      <dc:date>2022-11-27T16:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Create new columns from results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-new-columns-from-results/m-p/622127#M216250</link>
      <description>&lt;P&gt;mvindex is the answer.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;|union&lt;BR /&gt;&lt;SPAN&gt;[search index=Firewall BlockFromBadActor&lt;/SPAN&gt; | top src_ip by Date limit=5 | rename count as "IPCount"]&lt;BR /&gt;&lt;SPAN&gt;[search index=Firewall BlockFromBadActor&amp;nbsp;&lt;/SPAN&gt;| top dest_port by Date limit=10 | rename count as "PortCount"]&lt;BR /&gt;| stats values(*) as * by Date&lt;BR /&gt;| eval "IP #1" = mvindex(src_ip,0)&lt;BR /&gt;| eval "IP #2" = mvindex(src_ip,1)&lt;BR /&gt;| eval "IP #3" = mvindex(src_ip,2)&lt;BR /&gt;| eval "IP #4" = mvindex(src_ip,3)&lt;BR /&gt;| eval "IP #5" = mvindex(src_ip,4)&lt;BR /&gt;| eval "Count for IP #1" = mvindex(IPCount,0)&lt;BR /&gt;| eval "Count for IP #2" = mvindex(IPCount,1)&lt;BR /&gt;| eval "Count for IP #3" = mvindex(IPCount,2)&lt;BR /&gt;| eval "Count for IP #4" = mvindex(IPCount,3)&lt;BR /&gt;| eval "Count for IP #5" = mvindex(IPCount,4)&lt;BR /&gt;| eval "Port #1" = mvindex(dest_port,0)&lt;BR /&gt;| eval "Port #2" = mvindex(dest_port,1)&lt;BR /&gt;| eval "Port #3" = mvindex(dest_port,2)&lt;BR /&gt;| eval "Port #4" = mvindex(dest_port,3)&lt;BR /&gt;| eval "Port #5" = mvindex(dest_port,4)&lt;BR /&gt;| eval "Port #6" = mvindex(dest_port,5)&lt;BR /&gt;| eval "Port #7" = mvindex(dest_port,6)&lt;BR /&gt;| eval "Port #8" = mvindex(dest_port,7)&lt;BR /&gt;| eval "Port #9" = mvindex(dest_port,8)&lt;BR /&gt;| eval "Port #10" = mvindex(dest_port,9)&lt;BR /&gt;| eval "Count for Port #1" = mvindex(PortCount,0)&lt;BR /&gt;| eval "Count for Port #2" = mvindex(PortCount,1)&lt;BR /&gt;| eval "Count for Port #3" = mvindex(PortCount,2)&lt;BR /&gt;| eval "Count for Port #4" = mvindex(PortCount,3)&lt;BR /&gt;| eval "Count for Port #5" = mvindex(PortCount,4)&lt;BR /&gt;| eval "Count for Port #6" = mvindex(PortCount,5)&lt;BR /&gt;| eval "Count for Port #7" = mvindex(PortCount,6)&lt;BR /&gt;| eval "Count for Port #8" = mvindex(PortCount,7)&lt;BR /&gt;| eval "Count for Port #9" = mvindex(PortCount,8)&lt;BR /&gt;| eval "Count for Port #10" = mvindex(PortCount,9)&lt;BR /&gt;| fields Date,"IP #1","Count for IP #1","IP #2","Count for IP #2","IP #3","Count for IP #3","IP #4","Count for IP #4","IP #5","Count for IP #5","Port #1","Count for Port #1","Port #2","Count for Port #2","Port #3","Count for Port #3","Port #4","Count for Port #4","Port #5","Count for Port #5","Port #6","Count for Port #6","Port #7","Count for Port #7","Port #8","Count for Port #8","Port #9","Count for Port #9","Port #10","Count for Port #10"&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 21:04:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-new-columns-from-results/m-p/622127#M216250</guid>
      <dc:creator>CyberMage</dc:creator>
      <dc:date>2022-11-25T21:04:52Z</dc:date>
    </item>
  </channel>
</rss>

