Reporting

Modification

ramprakash
Explorer

 

 

Please advise.

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion

index =* source=*MIG* a_agent=* | bin spans=1d _time | stats count by _time a_agent | eval time=strftime(relative_time(now(),"@h"), "%F %T") | eval report="SBB0;INtegrationPLatform;".a_agent.";".count.";".time| fields - _* |table report

View solution in original post

0 Karma

to4kawa
Ultra Champion

index =* source=*MIG* a_agent=* | bin spans=1d _time | stats count by _time a_agent | eval time=strftime(relative_time(now(),"@h"), "%F %T") | eval report="SBB0;INtegrationPLatform;".a_agent.";".count.";".time| fields - _* |table report

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried transpose?

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...