<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: stats command help to convert a row to column in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127327#M34530</link>
    <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="aws-cloudwatch" ("i-2" OR "i-3" OR "i-4" OR "i-5" OR "i-6" OR "i-7" OR "i-8" OR "i-9" OR "i-11" OR "i-12" OR "i-13" OR "i-14" OR "i-15" OR "i-16" OR "i-17" OR "i-18" OR "i-19" OR "i-20" ) (metric_name=MemoryUsed OR metric_name=CPUUtilization OR metric_name=MemoryAvailable) | bin span=5m _time | eval MemoryUsed=if(metric_name="MemoryUsed",Average,0) | eval CPUUtilization=if(metric_name="CPUUtilization,Average,0) | eval MemoryAvailable=if(metric_name='MemoryAvailable',Average/1024,0) | stats avg(MemoryUsed) AS MemoryUsed avg(CPUUtilization) AS CPUUtilization avg(MemoryAvailable) ASMemoryAvailable BY _time, metric_dimensions
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 16 Jul 2015 21:22:52 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-07-16T21:22:52Z</dc:date>
    <item>
      <title>stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127325#M34528</link>
      <description>&lt;P&gt;Need your help,&lt;/P&gt;

&lt;P&gt;In the below query, we want to convert metric_name as column with values of avg_average, Can you please help us,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="aws-cloudwatch" ) ("i-2" OR "i-3" OR "i-4" OR "i-5" OR "i-6" OR "i-7" OR "i-8" OR "i-9" OR "i-11" OR "i-12" OR "i-13" OR "i-14" OR "i-15" OR "i-16" OR "i-17" OR "i-18" OR "i-19" OR "i-20" ) (metric_name=MemoryUsed OR metric_name=CPUUtilization OR metric_name=MemoryAvailable) | bin span=5m _time | eval Average=if(metric_name='MemoryAvailable',Average/1024,Average) | stats  avg(Average) as "avg_average"  by _time,  metric_dimensions,metric_name 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;from &lt;/P&gt;

&lt;P&gt;_time,  metric_dimensions,metric_name, avg_average&lt;/P&gt;

&lt;P&gt;to&lt;/P&gt;

&lt;P&gt;_time,  metric_dimensions, MemoryUsed, CPUUtilization, MemoryAvailable&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:43:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127325#M34528</guid>
      <dc:creator>dhavamanis</dc:creator>
      <dc:date>2020-09-29T06:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127326#M34529</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="aws-cloudwatch" ) ("i-2" OR "i-3" OR "i-4" OR "i-5" OR "i-6" OR "i-7" OR "i-8" OR "i-9" OR "i-11" OR "i-12" OR "i-13" OR "i-14" OR "i-15" OR "i-16" OR "i-17" OR "i-18" OR "i-19" OR "i-20" ) (metric_name=MemoryUsed OR metric_name=CPUUtilization OR metric_name=MemoryAvailable) | bin span=5m _time | eval Average=if(metric_name='MemoryAvailable',Average/1024,Average) | eval metric_dimensions=_time."#".metric_dimensions | chart avg(Average) as "avg_average"  over  metric_dimensions by metric_name | rex field=metric_dimensions "(?&amp;lt;_time&amp;gt;.*)#(?&amp;lt;metric_dimensions&amp;gt;.*)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 16 Jul 2015 21:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127326#M34529</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-07-16T21:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127327#M34530</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="aws-cloudwatch" ("i-2" OR "i-3" OR "i-4" OR "i-5" OR "i-6" OR "i-7" OR "i-8" OR "i-9" OR "i-11" OR "i-12" OR "i-13" OR "i-14" OR "i-15" OR "i-16" OR "i-17" OR "i-18" OR "i-19" OR "i-20" ) (metric_name=MemoryUsed OR metric_name=CPUUtilization OR metric_name=MemoryAvailable) | bin span=5m _time | eval MemoryUsed=if(metric_name="MemoryUsed",Average,0) | eval CPUUtilization=if(metric_name="CPUUtilization,Average,0) | eval MemoryAvailable=if(metric_name='MemoryAvailable',Average/1024,0) | stats avg(MemoryUsed) AS MemoryUsed avg(CPUUtilization) AS CPUUtilization avg(MemoryAvailable) ASMemoryAvailable BY _time, metric_dimensions
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 16 Jul 2015 21:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127327#M34530</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-16T21:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127328#M34531</link>
      <description>&lt;P&gt;I had a similar situation. The query work well for me except the output field positions.&lt;/P&gt;

&lt;P&gt;I am getting&lt;BR /&gt;
MemoryUsed, CPUUtilization, MemoryAvailable,_time, metric_dimensions&lt;/P&gt;

&lt;P&gt;Can you plz check and help.&lt;/P&gt;

&lt;P&gt;This is my query&lt;BR /&gt;
index=abc   | eval field=field1." | ".field2." | ".field3| chart count over field by field4 | rex field5=field "(?.&lt;EM&gt;)|(?.&lt;/EM&gt;)|(?.*)" | fields - field&lt;/P&gt;

&lt;P&gt;Output:&lt;BR /&gt;
field4_1    field4_2     field1     field2     field3&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127328#M34531</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2020-09-29T10:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127329#M34532</link>
      <description>&lt;P&gt;@Roopaul, just replace &lt;CODE&gt;fields - field&lt;/CODE&gt; with &lt;CODE&gt;table field4_1 field4_2 field1 field2 field3&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 23:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127329#M34532</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-08-12T23:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127330#M34533</link>
      <description>&lt;P&gt;field 4 is dynamically generated.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 23:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127330#M34533</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2016-08-12T23:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127331#M34534</link>
      <description>&lt;P&gt;If the value in field4 are know before hand, try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=abc | eval field=field1." | ".field2." | ".field3 | eval field4="00".field4 | chart count over field by field4 | rex field5=field "(?.)\|(?.)\|(?.*)" | table 00* field 1 field2 field3 | rename 00* AS *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;*&lt;STRONG&gt;&lt;EM&gt;else&lt;/EM&gt;&lt;/STRONG&gt;*&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=abc | eval field=field1." | ".field2." | ".field3 | eval field4="00".field4 | chart count over field by field4 | rex field5=field "(?.)\|(?.)\|(?.*)" | table field4_1 field4_2 field 1 field2 field3
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 13 Aug 2016 00:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127331#M34534</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-08-13T00:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: stats command help to convert a row to column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127332#M34535</link>
      <description>&lt;P&gt;The first one works well. Thanks a lot. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;P.S. &amp;gt; 1st to be used if values is unknown and 2nd if value is known.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2016 00:15:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-command-help-to-convert-a-row-to-column/m-p/127332#M34535</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2016-08-13T00:15:54Z</dc:date>
    </item>
  </channel>
</rss>

