hello all. i have a .csv report that gets generated regularly and that I'm monitoring. working fine there. trying to figure out how to display it because the data(events?) are in columns. is this possible? example data here.
Hosts | server1 | server2 |
IPLevel | median | median |
Tip1662 | N/A | N/A |
Tip1663 | PASSED | PASSED |
Tip1664 | FAILED | FAILED |
Tip1666 | PASSED | PASSED |
Tip1667 | PASSED | PASSED |
Tip1668 | PASSED | PASSED |
Tip1669 | N/A | N/A |
Tip1671 | PASSED | PASSED |
Tip1674 | SKIPPED | SKIPPED |
Tip1675 | FAILED | FAILED |
Tip1676 | PASSED | PASSED |
Tip1677 | PASSED | PASSED |
Tip1680 | PASSED | PASSED |
Tip1685 | PASSED | PASSED |
Tip1687 | PASSED | PASSED |
Tip1688 | SKIPPED | SKIPPED |
Tip1689 | SKIPPED | SKIPPED |
Tip1690 | FAILED | FAILED |
It is possible. If you're monitoring the CSV files then I'll presume they're in a Splunk index. If they're onboarded correctly (and could be a big "if") then this query will produce the desired table.
index=foo
| table Hosts server1 server2
It is possible. If you're monitoring the CSV files then I'll presume they're in a Splunk index. If they're onboarded correctly (and could be a big "if") then this query will produce the desired table.
index=foo
| table Hosts server1 server2
you nailed it. double checked and I had a typo in the stanza. the data I was seeing was from log files and not the final .csv.
I appreciate your time