Dashboards & Visualizations

Creating table by same unique id

abdulvehhaba
Path Finder

Hi

I have data like thisalt text

I want to dedup (group) uuid and create a price table in same row

Tags (1)
0 Karma
1 Solution

acharlieh
Influencer

Depending on what exactly you are expecting, there are at least a couple of different ways you could accomplish this:

<base search> | stats list(price) as price list(market) as market by uuid

This one uses Multivalue functions to give you the pairs of price and market

<base search> | chart limit=0 latest(price) over uuid by market

This one would have a row per uuid, with the price for each market in different columns by using the chart function.

I used the following as a base search to simulate your data:

| makeresults count=6 | streamstats count | eval uuid=if(count<=3,"A","B"), market=case(count%3=1,"MarketA",count%3=2,"MarketB",1=1,"MarketC"), price=random()  

View solution in original post

acharlieh
Influencer

Depending on what exactly you are expecting, there are at least a couple of different ways you could accomplish this:

<base search> | stats list(price) as price list(market) as market by uuid

This one uses Multivalue functions to give you the pairs of price and market

<base search> | chart limit=0 latest(price) over uuid by market

This one would have a row per uuid, with the price for each market in different columns by using the chart function.

I used the following as a base search to simulate your data:

| makeresults count=6 | streamstats count | eval uuid=if(count<=3,"A","B"), market=case(count%3=1,"MarketA",count%3=2,"MarketB",1=1,"MarketC"), price=random()  

abdulvehhaba
Path Finder

| chart limit=0 latest(price) over uuid by market

solve my problem thx, but it show only uuid and price i cannot see date, time etc

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...