Reporting

Include AND/OR operator in Pivot query

null0
New Member

Hi guys,
my problem is how to make working following query

| pivot Cisco_IOS_Event Cisco_IOS_Event count(host) AS "Count of host" avg(severity_id) AS "Average of severity_id" count(Cisco_IOS_Event) AS "Count of Cisco IOS Event" SPLITROW host AS host SORT 100 host ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 FILTER host is $host$

where $host$ refers to a field of a checkbox as

(host=10.29.28.) OR (host=10.29.72.)

i've no problem if network is only one, but AND or OR operator are making my head spinning 'cause not admitted if prefixed to PIVOT query.. "The pivot command can only be used as the first command on a search"

any idea abt how solve this?

many thx

0 Karma

renjith_nair
Legend

Hi @null0,

Try in in your filter

 | pivot Cisco_IOS_Event Cisco_IOS_Event count(host) AS "Count of host" avg(severity_id) AS "Average of severity_id" count(Cisco_IOS_Event) AS "Count of Cisco IOS Event" SPLITROW host AS host SORT 100 host ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 FILTER host in $host|s$

And set the token so that the values are in a format (value1,value2,value3,etc)

Reference : http://docs.splunk.com/Documentation/Splunk/7.1.1/SearchReference/Pivot#Descriptions_for_filter_elem...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

null0
New Member

guys! no idea how to solve this?

Please

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...