Reporting

Modification

ramprakash
Explorer

 

 

Please advise.

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion

index =* source=*MIG* a_agent=* | bin spans=1d _time | stats count by _time a_agent | eval time=strftime(relative_time(now(),"@h"), "%F %T") | eval report="SBB0;INtegrationPLatform;".a_agent.";".count.";".time| fields - _* |table report

View solution in original post

0 Karma

to4kawa
Ultra Champion

index =* source=*MIG* a_agent=* | bin spans=1d _time | stats count by _time a_agent | eval time=strftime(relative_time(now(),"@h"), "%F %T") | eval report="SBB0;INtegrationPLatform;".a_agent.";".count.";".time| fields - _* |table report

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried transpose?

0 Karma
Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...