Reporting

How can I reformat this report?

GersonGarcia
Path Finder

All,

I have this search

 

 

 

index=sro sourcetype=sro-cosmo "DL Cert OK" "Security Posture End of sweep report" | extract pairdelim="\n" kvdelim=":" 
| rex field=_raw "--ticket \'(?<ticket>.+)\' --summary" | fillnull value=0 | table _time ticket SA_Fail_Total_Count SA_Success_Count SA_Unreachables LP_Firmware_too_old | dedup _time ticket

 

 

 

That results in:

Screenshot 2022-11-28 155908.png

But my user wants in this format:

Screenshot 2022-11-28 155835.png

I am using Splunk 8.2.6.

Is there any way to format this report? So my user does not need to manipulate it in Excel?

Thank you,

Gerson Garcia

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

You cannot get the mangled tabulation supported by many spreadsheets (because Splunk really only do tables, not pseudo tables), but this can be close visually:

index=sro sourcetype=sro-cosmo "DL Cert OK" "Security Posture End of sweep report"
| extract pairdelim="\n" kvdelim=":" 
| rex field=_raw "--ticket \'(?<ticket>.+)\' --summary"
| fillnull value=0
| table _time ticket SA_Fail_Total_Count SA_Success_Count SA_Unreachables LP_Firmware_too_old
| dedup _time ticket
| eval headings = mvappend(strftime(_time, "%m/%d/%Y %H:%M"), "SA_Fail_Total_Count", "SA_Success_Count", "SA_Unreachables", "LP_Firmware_too_old")
| eval values = mvappend(ticket, SA_Fail_Total_Count, SA_Success_Count, SA_Unreachables, LP_Firmware_too_old)
| foreach headings values
    [eval <<FIELD>> = mvjoin(<<FIELD>>, "
")]
| fields headings values

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...