Splunk Enterprise

How to relate multi values ​​in a table

HigorAzevedo
Engager

Bom dia!
No cenário apresentado abaixo, não consigo associar os itens em uma tabela dentro do campo DbrfMatrial:
EngineeringCode, ItemDescription, ItemQty, SolutionCode



HigorAzevedo_0-1735932153347.png

HigorAzevedo_2-1735932233800.png

 

Usei o índice abaixo!

index=analise Task.TaskStatus="Concluído" Task.DbrfMaterial{}. SolutionCode="410 TROCA DO MOD/PLACA/PECA" State IN ("*") CustomerName IN ("*") ItemCode("*")
| mvexpand Task.DbrfMaterial{}. Código
de Engenharia| pesquise Task.DbrfMaterial{}. CódigoDeEngenharia="*"
| contagem de estatísticas por Task.DbrfMaterial{}. Código
de Engenharia| renomear contagem como Quantidade

| cabeça 20
| tabela Task.DbrfMaterial{}. Quantidade
do código de engenharia| ordenar -Quantidade
| appendcols [ search index=brazilcalldata Task.TaskStatus="Concluído" Task.DbrfMaterial.SolutionCode="410 TROCA DO MOD/PLACA/PECA" CustomerName IN ("*") State IN ("*") Task.DbrfMaterial.EngineeringCode="*" ItemCode = "*"
| stats count, sum(Task.DbrfMaterial.ItemQty) as TotalItemQty by Task.DbrfMaterial.EngineeringCode Task.DbrfMaterial.ItemDescription
| renomeie Task.DbrfMaterial.EngineeringCode como Item, Task.DbrfMaterial.ItemDescription como Descricao, TotalItemQty como "Qtde Itens"
| table Item Descrição "Qtde Itens" count
| sort - "Qtde Itens" ]
| eval TotalQuantity = Quantity + 'Qtde Itens'
| pesquise Task.DbrfMaterial{}. Código de Engenharia!=""
| tabela Task.DbrfMaterial{}. EngineeringCode Quantidade "Qtde Itens" TotalQuantity
Labels (2)
0 Karma

HigorAzevedo
Engager

marnall!
Thank you for your support in resolving this issue!

0 Karma

HigorAzevedo
Engager

Good morning Marnall!
Thank you very much for your support....with your help I managed to solve this problem!!!

0 Karma

marnall
Motivator

I am glad it is working 🙂

0 Karma

HigorAzevedo
Engager

I would like to view it in the format below

HigorAzevedo_1-1735937328670.png

 

 

 

0 Karma

marnall
Motivator

Talvez algo assim:

index=analise Task.TaskStatus="Concluído" Task.DbrfMaterial{}. SolutionCode="410 TROCA DO MOD/PLACA/PECA" State IN ("*") CustomerName IN ("*") ItemCode("*")
| spath path=Task.DbrfMaterial{} output=DbrfMaterial
| mvexpand DbrfMaterial
| table TaskNo DbrfMaterial
| spath input=DbrfMaterial path=
| table TaskNo EngineeringCode ItemDescription ItemQty SolutionCode



Como exatamente você gostaria que sua tablela fosse?

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...