Splunk Search

Convert confusion matrix to tabular form

dalmaua
Explorer

Hi,

I am trying to convert the result of applying the CorrelationMatrix algorithm which is given in a confusion matrix form like:

        AA     BB     CC

AA   1        0.1    0.2

BB    0.1     1      0.3  

CC   0.2     0.3    1

And I would like to convert it to a tabular form like:

AA BB 0.1
AA CC 0.2
BB AA 0.1 
BB CC 0.3
....

So far I tried with the untable command without success. Below you can see a sample of the code I have.

 

 

index="someIndex" 
| timechart span=1m count by someField
| fillnull value=0
| fit CorrelationMatrix method=pearson * 
| untable a, b, c

 

 

 

Any help would be much appreciated, 

Thanks!

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Assuming the first column is called index

| makeresults 
| eval _raw="index AA     BB     CC
AA    1        0.1    0.2
BB    0.1     1      0.3  
CC   0.2     0.3    1"
| multikv forceheader=1
| table index AA BB CC


| untable index name value
| where index!=name

View solution in original post

0 Karma

dalmaua
Explorer

Thanks, it worked!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming the first column is called index

| makeresults 
| eval _raw="index AA     BB     CC
AA    1        0.1    0.2
BB    0.1     1      0.3  
CC   0.2     0.3    1"
| multikv forceheader=1
| table index AA BB CC


| untable index name value
| where index!=name
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...