I have a saved search which lists results in this format
Field1 Field 2 Field 3
A aa aaa
B bb bbb
When I schedule a saved search and schedule it to send out a report via email, I need for the final report to contain row numbers as well - so its readable - preferably as the FIRST column (in the extracted csv -- or the inline format - we get to pick from either of these two options)
I would I do that ?
You can use streamstats
. To the search, add:
| streamstats count as row
| table row Field1 Field2 Field3
Did you check out the addtotls and addcoltotals command?
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Addcoltotals
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Addtotals
You can use streamstats
. To the search, add:
| streamstats count as row
| table row Field1 Field2 Field3
that worked like a charm ! thanks