Reporting

Include AND/OR operator in Pivot query

null0
New Member

Hi guys,
my problem is how to make working following query

| pivot Cisco_IOS_Event Cisco_IOS_Event count(host) AS "Count of host" avg(severity_id) AS "Average of severity_id" count(Cisco_IOS_Event) AS "Count of Cisco IOS Event" SPLITROW host AS host SORT 100 host ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 FILTER host is $host$

where $host$ refers to a field of a checkbox as

(host=10.29.28.) OR (host=10.29.72.)

i've no problem if network is only one, but AND or OR operator are making my head spinning 'cause not admitted if prefixed to PIVOT query.. "The pivot command can only be used as the first command on a search"

any idea abt how solve this?

many thx

0 Karma

renjith_nair
Legend

Hi @null0,

Try in in your filter

 | pivot Cisco_IOS_Event Cisco_IOS_Event count(host) AS "Count of host" avg(severity_id) AS "Average of severity_id" count(Cisco_IOS_Event) AS "Count of Cisco IOS Event" SPLITROW host AS host SORT 100 host ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1 FILTER host in $host|s$

And set the token so that the values are in a format (value1,value2,value3,etc)

Reference : http://docs.splunk.com/Documentation/Splunk/7.1.1/SearchReference/Pivot#Descriptions_for_filter_elem...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

null0
New Member

guys! no idea how to solve this?

Please

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...