Splunk Enterprise

How to relate multi values ​​in a table

HigorAzevedo
Engager

Bom dia!
No cenário apresentado abaixo, não consigo associar os itens em uma tabela dentro do campo DbrfMatrial:
EngineeringCode, ItemDescription, ItemQty, SolutionCode



HigorAzevedo_0-1735932153347.png

HigorAzevedo_2-1735932233800.png

 

Usei o índice abaixo!

index=analise Task.TaskStatus="Concluído" Task.DbrfMaterial{}. SolutionCode="410 TROCA DO MOD/PLACA/PECA" State IN ("*") CustomerName IN ("*") ItemCode("*")
| mvexpand Task.DbrfMaterial{}. Código
de Engenharia| pesquise Task.DbrfMaterial{}. CódigoDeEngenharia="*"
| contagem de estatísticas por Task.DbrfMaterial{}. Código
de Engenharia| renomear contagem como Quantidade

| cabeça 20
| tabela Task.DbrfMaterial{}. Quantidade
do código de engenharia| ordenar -Quantidade
| appendcols [ search index=brazilcalldata Task.TaskStatus="Concluído" Task.DbrfMaterial.SolutionCode="410 TROCA DO MOD/PLACA/PECA" CustomerName IN ("*") State IN ("*") Task.DbrfMaterial.EngineeringCode="*" ItemCode = "*"
| stats count, sum(Task.DbrfMaterial.ItemQty) as TotalItemQty by Task.DbrfMaterial.EngineeringCode Task.DbrfMaterial.ItemDescription
| renomeie Task.DbrfMaterial.EngineeringCode como Item, Task.DbrfMaterial.ItemDescription como Descricao, TotalItemQty como "Qtde Itens"
| table Item Descrição "Qtde Itens" count
| sort - "Qtde Itens" ]
| eval TotalQuantity = Quantity + 'Qtde Itens'
| pesquise Task.DbrfMaterial{}. Código de Engenharia!=""
| tabela Task.DbrfMaterial{}. EngineeringCode Quantidade "Qtde Itens" TotalQuantity
Labels (2)
0 Karma

HigorAzevedo
Engager

marnall!
Thank you for your support in resolving this issue!

0 Karma

HigorAzevedo
Engager

Good morning Marnall!
Thank you very much for your support....with your help I managed to solve this problem!!!

0 Karma

marnall
Motivator

I am glad it is working 🙂

0 Karma

HigorAzevedo
Engager

I would like to view it in the format below

HigorAzevedo_1-1735937328670.png

 

 

 

0 Karma

marnall
Motivator

Talvez algo assim:

index=analise Task.TaskStatus="Concluído" Task.DbrfMaterial{}. SolutionCode="410 TROCA DO MOD/PLACA/PECA" State IN ("*") CustomerName IN ("*") ItemCode("*")
| spath path=Task.DbrfMaterial{} output=DbrfMaterial
| mvexpand DbrfMaterial
| table TaskNo DbrfMaterial
| spath input=DbrfMaterial path=
| table TaskNo EngineeringCode ItemDescription ItemQty SolutionCode



Como exatamente você gostaria que sua tablela fosse?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...