Dashboards & Visualizations

Group row values to column - Summary Index

sreerajrajan
New Member

My summary index search results for a timechart is as below: (index="siabc" | sitimechart sum(Count) by Host)

Time Host Count
19:15 server1 4446
19:15 server2 6536
19:15 server3 5863
19:15 server4 7822
19:20 server1 4461
19:20 server2 6244
19:20 server3 5565
19:20 server4 7713
19:25 server1 4478
19:25 server2 6060
19:25 server3 5715
19:25 server4 7998

How can i change to
Time server1 server2 server3 server4
19:15 4446 6536 5863 7822
19:20 4461 6244 5565 7713
19:25 4478 6060 5715 7998

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust
... mysummarysearch ...
| chart sum(Count) over Time by Host

Give that a try, let us know how it works!

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust
... mysummarysearch ...
| chart sum(Count) over Time by Host

Give that a try, let us know how it works!

0 Karma

sreerajrajan
New Member

Thanks! it worked.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...