Dashboards & Visualizations

Table in Splunk

Roopashree
Observer

Hi,

I wanted to create a table as below. I am extracting Status and Reason using rex. How can I create this. Count column should count the events- I used stats count by ..

Roopashree_0-1711641222255.png

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Roopashree,

Splunk isn't Excel, so you cannot merge two cels, you could have the NOT_OK value in both the rows:

<your_search>
| rex 1
| rex 2
| stats count BY Status Reasons

please next time add also the sample in text mode.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...