<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a dynamic table based on one search result? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132240#M36051</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I think trendline and timewrap are not what I need.&lt;BR /&gt;
Also I don't want to use 3rd party.&lt;/P&gt;

&lt;P&gt;What I did now (and solved a part of the problem):&lt;/P&gt;

&lt;P&gt;Created some small txt-Files manually with my historical data (timestamp, and used storage).&lt;BR /&gt;
So I'am able to get a table with the row  (line from 2001 until 2014) and a second row with  for each year.&lt;/P&gt;

&lt;P&gt;With the EVAL (for converting) and DELTA command I created an new row to calculate my growth.&lt;BR /&gt;
Also with some more EVAL and STATS I created a row to compare my growth with the market forecast (storage doubling all 2 years).&lt;/P&gt;

&lt;P&gt;After that I placed a input field to the panel, so I can set a static value for forecast-year.&lt;BR /&gt;
So I have all values I need to calculate the growth from 2014 to eg. 2018 or 2020, etc.&lt;/P&gt;

&lt;P&gt;The table (and graph) goes now from year 2001 until 2014 and then the next and last row is year 2018.&lt;BR /&gt;
So I have the right result now.&lt;/P&gt;

&lt;P&gt;But it would be fine to see the years between 2014 and 2018 too.&lt;BR /&gt;
I found no way to create them "dynamicly" (like a for loop).&lt;/P&gt;

&lt;P&gt;I did't used TIMECHART, because my historical data _time has not the right stamp in SPLUNK.&lt;BR /&gt;
I only worked with ... | CHART values(used) by mytime | ...&lt;/P&gt;

&lt;P&gt;I created the txt files, because I startet SPLUNK in this environment after 2014.&lt;/P&gt;

&lt;P&gt;thx,&lt;BR /&gt;
sven&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2015 12:11:08 GMT</pubDate>
    <dc:creator>outofheapspace</dc:creator>
    <dc:date>2015-07-31T12:11:08Z</dc:date>
    <item>
      <title>How to create a dynamic table based on one search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132237#M36048</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm building a line graph with a field with "UsedSpaceGB" from the year 2009 until now so I can see the growth of data. That's working fine.&lt;/P&gt;

&lt;P&gt;Now additionally, I want to build a second line. This second line should be the line of the forecast from 2009 until 2019 with a factor.&lt;BR /&gt;
So the final graph will show the real growth and the growth estimated in 2009.&lt;/P&gt;

&lt;P&gt;The factor is given. I can put them to a variable (eval command). The first Year is given by a search result.&lt;/P&gt;

&lt;P&gt;Now my problem is how to create the search. I think I need to build a dynamic Table with a "loop":&lt;BR /&gt;
Take the year 2009... add 1 Year ... do that 10 times... put it to a table... fill in the estimated time for each year based on the factor and the value from past year...&lt;/P&gt;

&lt;P&gt;I have no idea how to do that. &lt;BR /&gt;
Later, I want to make it more dynamic... changing the factor, changing beginning year and end year.&lt;BR /&gt;
I want to do that with onboard tools.&lt;/P&gt;

&lt;P&gt;Anybody out there with a hint for me?&lt;/P&gt;

&lt;P&gt;Many thanks,&lt;BR /&gt;
sven&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 11:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132237#M36048</guid>
      <dc:creator>outofheapspace</dc:creator>
      <dc:date>2015-07-22T11:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dynamic table based on one search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132238#M36049</link>
      <description>&lt;P&gt;Why you go for trendline &lt;/P&gt;

&lt;P&gt;your search| stats count by source Time| trendline sma2(count) as trend&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/SearchReference/Trendline"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.4/SearchReference/Trendline&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 15:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132238#M36049</guid>
      <dc:creator>senthilgoa</dc:creator>
      <dc:date>2015-07-22T15:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dynamic table based on one search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132239#M36050</link>
      <description>&lt;P&gt;I am not sure I get what you are trying to do but I am pretty sure that you will be able to make good use of the &lt;CODE&gt;timewrap&lt;/CODE&gt; app to do it:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1645/"&gt;https://splunkbase.splunk.com/app/1645/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2015 03:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132239#M36050</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-29T03:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dynamic table based on one search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132240#M36051</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I think trendline and timewrap are not what I need.&lt;BR /&gt;
Also I don't want to use 3rd party.&lt;/P&gt;

&lt;P&gt;What I did now (and solved a part of the problem):&lt;/P&gt;

&lt;P&gt;Created some small txt-Files manually with my historical data (timestamp, and used storage).&lt;BR /&gt;
So I'am able to get a table with the row  (line from 2001 until 2014) and a second row with  for each year.&lt;/P&gt;

&lt;P&gt;With the EVAL (for converting) and DELTA command I created an new row to calculate my growth.&lt;BR /&gt;
Also with some more EVAL and STATS I created a row to compare my growth with the market forecast (storage doubling all 2 years).&lt;/P&gt;

&lt;P&gt;After that I placed a input field to the panel, so I can set a static value for forecast-year.&lt;BR /&gt;
So I have all values I need to calculate the growth from 2014 to eg. 2018 or 2020, etc.&lt;/P&gt;

&lt;P&gt;The table (and graph) goes now from year 2001 until 2014 and then the next and last row is year 2018.&lt;BR /&gt;
So I have the right result now.&lt;/P&gt;

&lt;P&gt;But it would be fine to see the years between 2014 and 2018 too.&lt;BR /&gt;
I found no way to create them "dynamicly" (like a for loop).&lt;/P&gt;

&lt;P&gt;I did't used TIMECHART, because my historical data _time has not the right stamp in SPLUNK.&lt;BR /&gt;
I only worked with ... | CHART values(used) by mytime | ...&lt;/P&gt;

&lt;P&gt;I created the txt files, because I startet SPLUNK in this environment after 2014.&lt;/P&gt;

&lt;P&gt;thx,&lt;BR /&gt;
sven&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2015 12:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dynamic-table-based-on-one-search-result/m-p/132240#M36051</guid>
      <dc:creator>outofheapspace</dc:creator>
      <dc:date>2015-07-31T12:11:08Z</dc:date>
    </item>
  </channel>
</rss>

