<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create Table Group Results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151185#M42368</link>
    <description>&lt;P&gt;You also need rename option as it is in lguinn's answer&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jul 2014 18:30:05 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2014-07-21T18:30:05Z</dc:date>
    <item>
      <title>Create Table Group Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151182#M42365</link>
      <description>&lt;P&gt;I have the following data:&lt;BR /&gt;
&lt;TABLE class="tg"&gt;&lt;BR /&gt;
  &lt;TBODY&gt;&lt;TR&gt;&lt;BR /&gt;
    &lt;TH class="tg-031e"&gt;DateTime&lt;/TH&gt;&lt;BR /&gt;
    &lt;TH class="tg-031e"&gt;GroupName&lt;/TH&gt;&lt;BR /&gt;
    &lt;TH class="tg-031e"&gt;Count&lt;/TH&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-14T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group1&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;15&lt;BR /&gt;&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-14T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group2&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;17&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-14T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group3&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;19&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-15T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group1&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;18&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-15T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group2&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;20&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-15T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group3&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-16T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group1&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;19&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-16T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group2&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;20&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-16T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group3&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-17T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group1&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;22&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-17T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group2&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
  &lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-17T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group3&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;30&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
&lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-18T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group1&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
&lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-18T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group2&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;32&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
&lt;TR&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;2014-07-18T12:00:00&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;Group3&lt;/TD&gt;&lt;BR /&gt;
    &lt;TD class="tg-031e"&gt;35&lt;/TD&gt;&lt;BR /&gt;
  &lt;/TR&gt;&lt;BR /&gt;
&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR /&gt;
&lt;BR /&gt;&lt;BR /&gt;
What I want is to have Splunk display it like so:&lt;BR /&gt;
&lt;BR /&gt;&lt;/P&gt;

&lt;TABLE class="tg"&gt;
  &lt;TBODY&gt;&lt;TR&gt;
    &lt;TH class="tg-031e"&gt;Group&lt;/TH&gt;
    &lt;TH class="tg-031e"&gt;Monday&lt;/TH&gt;
    &lt;TH class="tg-031e"&gt;Tuesday&lt;/TH&gt;
    &lt;TH class="tg-031e"&gt;Wednesday&lt;/TH&gt;
    &lt;TH class="tg-031e"&gt;Thursday&lt;/TH&gt;
    &lt;TH class="tg-031e"&gt;Friday&lt;/TH&gt;

  &lt;/TR&gt;
  &lt;TR&gt;
    &lt;TD class="tg-031e"&gt;Group1&lt;BR /&gt;&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;15&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;18&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;19&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;22&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;
  &lt;/TR&gt;
  &lt;TR&gt;
    &lt;TD class="tg-031e"&gt;Group2&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;17&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;20&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;20&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;32&lt;/TD&gt;
  &lt;/TR&gt;
  &lt;TR&gt;
    &lt;TD class="tg-031e"&gt;Group3&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;19&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;25&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;30&lt;/TD&gt;
    &lt;TD class="tg-031e"&gt;35&lt;/TD&gt;

  &lt;/TR&gt;
&lt;/TBODY&gt;&lt;/TABLE&gt;

&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;
This will only ever display 1 week's worth of data, so the width of the table isn't a concern.  Thanks in advance for any assistance! &lt;/P&gt;

&lt;P&gt;So far, I have this to pull the weekday out.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;search&amp;gt; | eval WeekDay=upper(substr(date_wday,1,1)).substr(date_wday,2)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151182#M42365</guid>
      <dc:creator>caviman2201</dc:creator>
      <dc:date>2014-07-21T18:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Create Table Group Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151183#M42366</link>
      <description>&lt;P&gt;I would do it this way&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| eval Weekday = strftime(_time,"%a")
| chart first(Count) as Count by GroupName Weekday
| rename GroupName as Group
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Assuming that there is only one event for each group and each day of week (that's why &lt;CODE&gt;first&lt;/CODE&gt; works here).&lt;/P&gt;

&lt;P&gt;Oops, just realized that this is likely to sort by the name of the day of the week, rather than what you want. So try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| eval Weekday = strftime(_time,"%w %a")
| chart first(Count) as Count by GroupName Weekday
| rename GroupName as Group
| rename "0 Sun" as "Sun", "1 Mon" as "Mon", "2 Tue" as "Tue", "3 Wed" as "Wed", "4 Thu" as "Thu", "5 Fri" as "Fri", "6 Sat" as "Sat"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151183#M42366</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-07-21T18:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Create Table Group Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151184#M42367</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;P&gt;Assuming that there will be more than one Count for a day and group combination&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;search&amp;gt; | eval WeekDay=upper(substr(date_wday,1,1)).substr(date_wday,2) | chart sum(Count) as Count by GroupName WeekDay
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151184#M42367</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-21T18:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Create Table Group Results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151185#M42368</link>
      <description>&lt;P&gt;You also need rename option as it is in lguinn's answer&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:30:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-Table-Group-Results/m-p/151185#M42368</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-21T18:30:05Z</dc:date>
    </item>
  </channel>
</rss>

