Reporting

Include AND/OR operator in Pivot query

null0
New Member

Hi guys,
my problem is how to make working following query

| pivot Cisco_IOS_Event Cisco_IOS_Event count(host) AS "Count of host" avg(severity_id) AS "Average of severity_id" count(Cisco_IOS_Event) AS "Count of Cisco IOS Event" SPLITROW host AS host SORT 100 host ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 FILTER host is $host$

where $host$ refers to a field of a checkbox as

(host=10.29.28.) OR (host=10.29.72.)

i've no problem if network is only one, but AND or OR operator are making my head spinning 'cause not admitted if prefixed to PIVOT query.. "The pivot command can only be used as the first command on a search"

any idea abt how solve this?

many thx

0 Karma

renjith_nair
Legend

Hi @null0,

Try in in your filter

 | pivot Cisco_IOS_Event Cisco_IOS_Event count(host) AS "Count of host" avg(severity_id) AS "Average of severity_id" count(Cisco_IOS_Event) AS "Count of Cisco IOS Event" SPLITROW host AS host SORT 100 host ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 FILTER host in $host|s$

And set the token so that the values are in a format (value1,value2,value3,etc)

Reference : http://docs.splunk.com/Documentation/Splunk/7.1.1/SearchReference/Pivot#Descriptions_for_filter_elem...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

null0
New Member

guys! no idea how to solve this?

Please

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...