Splunk Search

Create table with nested columns

ShaneNewman
Motivator

I am not sure what the proper terminology is for this so I have attached captures below to better illustrate my goal.

I am trying to make a data set that looks like this:
alt text

And format it to look like this:
alt text

I have tried untable/xyseries but it does not seems to work because I have more than 1 "y" field. I basically want to recreate an excel pivot table in Splunk to automate a daily task.

Tags (2)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

ShaneNewman
Motivator

This seems like an oversight by Splunk if they really want to be competitive...

0 Karma

khutchinson_spl
Splunk Employee
Splunk Employee

Shane. I am surprised. I will figure this out for you personally. I am sorry for the tardiness in getting this resolved for you. Your contributions to Splunk are numerous.

0 Karma

skahal_personal
New Member

Still not possible?

0 Karma

koshiiiii
New Member

Hey ! Is there any update ?

0 Karma

rmungonda
Engager

Is this still not possible? I am looking for similar functionality. Thanks.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...