<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk create a table using multiple fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657433#M227078</link>
    <description>&lt;P&gt;In your stats statement, add the other fields you need using evals: count(eval(status="Success")) as Success, count(eval(status="Failed")) as Failed, and remove the status from the by clause. After the stats, do an eval to calculate your percentages.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 14:14:49 GMT</pubDate>
    <dc:creator>etoombs</dc:creator>
    <dc:date>2023-09-13T14:14:49Z</dc:date>
    <item>
      <title>How to use Splunk to create a table using multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657429#M227076</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I want to create a splunk table using multiple fields. Let me explain the scenario&lt;BR /&gt;I have the following fields&lt;/P&gt;
&lt;P&gt;Name&lt;BR /&gt;Role (multiple roles will exist for each name)&lt;BR /&gt;HTTPrequest (There are multiple response as 2**,3**,4** and 5**)&lt;/P&gt;
&lt;P&gt;My final output&amp;nbsp; should be when the query is ran, It should the group the data in the below format for every day&lt;/P&gt;
&lt;TABLE width="609"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;Date&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;Name&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;Role&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;Success&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;Failed&amp;nbsp;&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;Total&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;Failed %&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;Rambo&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;Team lead&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;0&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;Rambo&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;Manager&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;10&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;110&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;10&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;King&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;operator&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;2000&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;2100&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;5&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;02-Jan-23&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;King&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;Manager&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;0&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;03-Jan-23&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;cheesy&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;Manager&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;100&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;10&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;110&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;10&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.7812px"&gt;04-Jan-23&lt;/TD&gt;
&lt;TD width="86.8672px"&gt;cheesy&lt;/TD&gt;
&lt;TD width="86.9297px"&gt;Team lead&lt;/TD&gt;
&lt;TD width="86.9141px"&gt;4000&lt;/TD&gt;
&lt;TD width="86.8438px"&gt;600&lt;/TD&gt;
&lt;TD width="86.8047px"&gt;4600&lt;/TD&gt;
&lt;TD width="86.8594px"&gt;15&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, What I tried is&amp;nbsp;&lt;BR /&gt;index=ABCD&lt;BR /&gt;| bucket _time span=1d&lt;BR /&gt;| eval status=case(HTTPrequest &amp;lt; 400,"Success",HTTPrequest &amp;gt; 399,"Failed" )&lt;BR /&gt;| stats count by _time Name Role&amp;nbsp;status&lt;BR /&gt;&lt;BR /&gt;This works something as below but I need the success and failure&amp;nbsp; in to 2 seperate columns as I have shown above and also I need to add the failed % and total&lt;/P&gt;
&lt;TABLE border="0" width="435" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="87" height="21"&gt;Date&lt;/TD&gt;
&lt;TD width="87"&gt;Name&lt;/TD&gt;
&lt;TD width="87"&gt;Role&lt;/TD&gt;
&lt;TD width="87"&gt;HTTPStatus&lt;/TD&gt;
&lt;TD width="87"&gt;COUNT&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD&gt;Rambo&lt;/TD&gt;
&lt;TD&gt;Team lead&lt;/TD&gt;
&lt;TD&gt;Success&lt;/TD&gt;
&lt;TD&gt;100&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD&gt;Rambo&lt;/TD&gt;
&lt;TD&gt;Team lead&lt;/TD&gt;
&lt;TD&gt;Failed&lt;/TD&gt;
&lt;TD&gt;0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD&gt;Rambo&lt;/TD&gt;
&lt;TD&gt;Manager&lt;/TD&gt;
&lt;TD&gt;Success&lt;/TD&gt;
&lt;TD&gt;100&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD&gt;Rambo&lt;/TD&gt;
&lt;TD&gt;Manager&lt;/TD&gt;
&lt;TD&gt;Failed&lt;/TD&gt;
&lt;TD&gt;10&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD&gt;King&lt;/TD&gt;
&lt;TD&gt;operator&lt;/TD&gt;
&lt;TD&gt;Success&lt;/TD&gt;
&lt;TD&gt;2000&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;01-Jan-23&lt;/TD&gt;
&lt;TD&gt;King&lt;/TD&gt;
&lt;TD&gt;operator&lt;/TD&gt;
&lt;TD&gt;Failed&lt;/TD&gt;
&lt;TD&gt;200&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;02-Jan-23&lt;/TD&gt;
&lt;TD&gt;King&lt;/TD&gt;
&lt;TD&gt;Manager&lt;/TD&gt;
&lt;TD&gt;Success&lt;/TD&gt;
&lt;TD&gt;10&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;03-Jan-23&lt;/TD&gt;
&lt;TD&gt;cheesy&lt;/TD&gt;
&lt;TD&gt;Manager&lt;/TD&gt;
&lt;TD&gt;Success&lt;/TD&gt;
&lt;TD&gt;300&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="21"&gt;04-Jan-23&lt;/TD&gt;
&lt;TD&gt;cheesy&lt;/TD&gt;
&lt;TD&gt;Team lead&lt;/TD&gt;
&lt;TD&gt;Success&lt;/TD&gt;
&lt;TD&gt;400&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I used the chart count over X by Y but this allows me to use only 2 fields and not more than 2&lt;/P&gt;
&lt;P&gt;Please could you suggest me on how to get this sorted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 16:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657429#M227076</guid>
      <dc:creator>suvi6789</dc:creator>
      <dc:date>2023-09-14T16:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk create a table using multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657433#M227078</link>
      <description>&lt;P&gt;In your stats statement, add the other fields you need using evals: count(eval(status="Success")) as Success, count(eval(status="Failed")) as Failed, and remove the status from the by clause. After the stats, do an eval to calculate your percentages.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 14:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657433#M227078</guid>
      <dc:creator>etoombs</dc:creator>
      <dc:date>2023-09-13T14:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk create a table using multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657439#M227082</link>
      <description>&lt;P&gt;Hi etoombs,&lt;/P&gt;&lt;P&gt;Many thanks for the suggestion, I got that sorted.ta&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 15:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657439#M227082</guid>
      <dc:creator>suvi6789</dc:creator>
      <dc:date>2023-09-13T15:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk create a table using multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657440#M227083</link>
      <description>&lt;P&gt;It worked perfectly for me. Thank you again.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 15:23:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-Splunk-to-create-a-table-using-multiple-fields/m-p/657440#M227083</guid>
      <dc:creator>suvi6789</dc:creator>
      <dc:date>2023-09-13T15:23:48Z</dc:date>
    </item>
  </channel>
</rss>

