Getting Data In

Field values as headers merged with existing fields


Error Scheduled Successful Failed FieldB FieldC FieldD
10 100 500 5 String String String

Desired output is above :

I would like a table showing a count of the statuses in Field A - as column headers (Errors, Successful, failed etc) inline with fields B > D
How to bring this together ?

i have tried with transpose=header_field=FieldA and also played with xyseries - but unsuccessful so far.


Tags (1)
0 Karma


hi @Esky73
Not clear at all... what are your fields and what is your output? can you provide a better desired output sample?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...