Hi All,
I have created the below table using a query as (...... | stats count as Total by Domain,Act_Status)
| Domain | Act_Status | Total |
| A | RUNNING | 65 |
| A | STOPPED | 2 |
| B | RUNNING | 75 |
| C | RUNNING | 2 |
| C | STOPPED | 2 |
| D | RUNNING | 26 |
| D | STOPPED | 6 |
| E | RUNNING | 43 |
Here I want to create the table in a way that the common Domains are in a row like below:
| Domain | Act_Status | Total |
| A | RUNNING STOPPED | 65 2 |
| B | RUNNING | 75 |
| C | RUNNING STOPPED | 2 2 |
| D | RUNNING STOPPED | 26 6 |
| E | RUNNING | 43 |
Please help a modify the query to get the desired output.
Thank you.
Add this to your search
| stats list(Act_Status) as Act_Status list(Total) as Total by Domain
| table Domain Act_Status Total
Thank you very much for the support. That query works fine now.
Add this to your search
| stats list(Act_Status) as Act_Status list(Total) as Total by Domain
| table Domain Act_Status Total
Can you please try this?
YOUR_SEARCH
| stats values(Act_Status) as Act_Status values(Total) as Total by Domain
My Sample Search :
| makeresults | eval _raw="Domain Act_Status Total
A RUNNING 65
A STOPPED 2
B RUNNING 75
C RUNNING 2
C STOPPED 2
D RUNNING 26
D STOPPED 6
E RUNNING 43" | multikv forceheader=1
| stats values(Act_Status) as Act_Status values(Total) as Total by Domain
Thanks
KV
▄︻̷̿┻̿═━一
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.