Splunk Enterprise

How to relate multi values ​​in a table

HigorAzevedo
Engager

Bom dia!
No cenário apresentado abaixo, não consigo associar os itens em uma tabela dentro do campo DbrfMatrial:
EngineeringCode, ItemDescription, ItemQty, SolutionCode



HigorAzevedo_0-1735932153347.png

HigorAzevedo_2-1735932233800.png

 

Usei o índice abaixo!

index=analise Task.TaskStatus="Concluído" Task.DbrfMaterial{}. SolutionCode="410 TROCA DO MOD/PLACA/PECA" State IN ("*") CustomerName IN ("*") ItemCode("*")
| mvexpand Task.DbrfMaterial{}. Código
de Engenharia| pesquise Task.DbrfMaterial{}. CódigoDeEngenharia="*"
| contagem de estatísticas por Task.DbrfMaterial{}. Código
de Engenharia| renomear contagem como Quantidade

| cabeça 20
| tabela Task.DbrfMaterial{}. Quantidade
do código de engenharia| ordenar -Quantidade
| appendcols [ search index=brazilcalldata Task.TaskStatus="Concluído" Task.DbrfMaterial.SolutionCode="410 TROCA DO MOD/PLACA/PECA" CustomerName IN ("*") State IN ("*") Task.DbrfMaterial.EngineeringCode="*" ItemCode = "*"
| stats count, sum(Task.DbrfMaterial.ItemQty) as TotalItemQty by Task.DbrfMaterial.EngineeringCode Task.DbrfMaterial.ItemDescription
| renomeie Task.DbrfMaterial.EngineeringCode como Item, Task.DbrfMaterial.ItemDescription como Descricao, TotalItemQty como "Qtde Itens"
| table Item Descrição "Qtde Itens" count
| sort - "Qtde Itens" ]
| eval TotalQuantity = Quantity + 'Qtde Itens'
| pesquise Task.DbrfMaterial{}. Código de Engenharia!=""
| tabela Task.DbrfMaterial{}. EngineeringCode Quantidade "Qtde Itens" TotalQuantity
Labels (2)
0 Karma

HigorAzevedo
Engager

marnall!
Thank you for your support in resolving this issue!

0 Karma

HigorAzevedo
Engager

Good morning Marnall!
Thank you very much for your support....with your help I managed to solve this problem!!!

0 Karma

marnall
Motivator

I am glad it is working 🙂

0 Karma

HigorAzevedo
Engager

I would like to view it in the format below

HigorAzevedo_1-1735937328670.png

 

 

 

0 Karma

marnall
Motivator

Talvez algo assim:

index=analise Task.TaskStatus="Concluído" Task.DbrfMaterial{}. SolutionCode="410 TROCA DO MOD/PLACA/PECA" State IN ("*") CustomerName IN ("*") ItemCode("*")
| spath path=Task.DbrfMaterial{} output=DbrfMaterial
| mvexpand DbrfMaterial
| table TaskNo DbrfMaterial
| spath input=DbrfMaterial path=
| table TaskNo EngineeringCode ItemDescription ItemQty SolutionCode



Como exatamente você gostaria que sua tablela fosse?

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...