Splunk Enterprise

Format to show data

Gabriel_CCI
Explorer

Hi.

Colleagues.
Somebody help me?

I have this query by current day (figure 1)

index=xxxx sourcetype=xxx earliest=-d@d latest=now |table control indicador cumplimiento| sort control
|chart values(cumplimiento) over control by indicador

the fields are: Empleo, Huérfanas, Uso, Control _time and Month

figure1.png

My problem is, I need also show data as showing in figure 2 (by month), but I don´t find the way to show as the figure (with month on top) 

figure 2.png

 

Somebody were a similar problem?

Labels (1)
Tags (1)
0 Karma

Gabriel_CCI
Explorer

 Hi, Isn´t possible with join of chart?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

No, the view you have is a table view and table views have unique column names, and do not have additional headers such as month as you have shown in your graphic.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is not possible with a single standard visualisation - you could have multiple panels with a different month in each panel.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...