- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

hello all. i have a .csv report that gets generated regularly and that I'm monitoring. working fine there. trying to figure out how to display it because the data(events?) are in columns. is this possible? example data here.
Hosts | server1 | server2 |
IPLevel | median | median |
Tip1662 | N/A | N/A |
Tip1663 | PASSED | PASSED |
Tip1664 | FAILED | FAILED |
Tip1666 | PASSED | PASSED |
Tip1667 | PASSED | PASSED |
Tip1668 | PASSED | PASSED |
Tip1669 | N/A | N/A |
Tip1671 | PASSED | PASSED |
Tip1674 | SKIPPED | SKIPPED |
Tip1675 | FAILED | FAILED |
Tip1676 | PASSED | PASSED |
Tip1677 | PASSED | PASSED |
Tip1680 | PASSED | PASSED |
Tip1685 | PASSED | PASSED |
Tip1687 | PASSED | PASSED |
Tip1688 | SKIPPED | SKIPPED |
Tip1689 | SKIPPED | SKIPPED |
Tip1690 | FAILED | FAILED |
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


It is possible. If you're monitoring the CSV files then I'll presume they're in a Splunk index. If they're onboarded correctly (and could be a big "if") then this query will produce the desired table.
index=foo
| table Hosts server1 server2
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


It is possible. If you're monitoring the CSV files then I'll presume they're in a Splunk index. If they're onboarded correctly (and could be a big "if") then this query will produce the desired table.
index=foo
| table Hosts server1 server2
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

you nailed it. double checked and I had a typo in the stanza. the data I was seeing was from log files and not the final .csv.
I appreciate your time
