Splunk Search

Create table with nested columns

ShaneNewman
Motivator

I am not sure what the proper terminology is for this so I have attached captures below to better illustrate my goal.

I am trying to make a data set that looks like this:
alt text

And format it to look like this:
alt text

I have tried untable/xyseries but it does not seems to work because I have more than 1 "y" field. I basically want to recreate an excel pivot table in Splunk to automate a daily task.

Tags (2)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

ShaneNewman
Motivator

This seems like an oversight by Splunk if they really want to be competitive...

0 Karma

khutchinson_spl
Splunk Employee
Splunk Employee

Shane. I am surprised. I will figure this out for you personally. I am sorry for the tardiness in getting this resolved for you. Your contributions to Splunk are numerous.

It's a great day to be Splunkin'!
0 Karma

skahal_personal
New Member

Still not possible?

0 Karma

koshiiiii
New Member

Hey ! Is there any update ?

0 Karma

rmungonda
Engager

Is this still not possible? I am looking for similar functionality. Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...