Splunk Search

Create table with nested columns

ShaneNewman
Motivator

I am not sure what the proper terminology is for this so I have attached captures below to better illustrate my goal.

I am trying to make a data set that looks like this:
alt text

And format it to look like this:
alt text

I have tried untable/xyseries but it does not seems to work because I have more than 1 "y" field. I basically want to recreate an excel pivot table in Splunk to automate a daily task.

Tags (2)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

ShaneNewman
Motivator

This seems like an oversight by Splunk if they really want to be competitive...

0 Karma

khutchinson_spl
Splunk Employee
Splunk Employee

Shane. I am surprised. I will figure this out for you personally. I am sorry for the tardiness in getting this resolved for you. Your contributions to Splunk are numerous.

0 Karma

skahal_personal
New Member

Still not possible?

0 Karma

koshiiiii
New Member

Hey ! Is there any update ?

0 Karma

rmungonda
Engager

Is this still not possible? I am looking for similar functionality. Thanks.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...