Splunk Search

Create table with nested columns

ShaneNewman
Motivator

I am not sure what the proper terminology is for this so I have attached captures below to better illustrate my goal.

I am trying to make a data set that looks like this:
alt text

And format it to look like this:
alt text

I have tried untable/xyseries but it does not seems to work because I have more than 1 "y" field. I basically want to recreate an excel pivot table in Splunk to automate a daily task.

Tags (2)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

This is not currently possible with native visualizations. However, you can create and extend the SplunkJS stack such that you can create the table as shown. Would take some skills with Javascript and HTML.

ShaneNewman
Motivator

This seems like an oversight by Splunk if they really want to be competitive...

0 Karma

khutchinson_spl
Splunk Employee
Splunk Employee

Shane. I am surprised. I will figure this out for you personally. I am sorry for the tardiness in getting this resolved for you. Your contributions to Splunk are numerous.

0 Karma

skahal_personal
New Member

Still not possible?

0 Karma

koshiiiii
New Member

Hey ! Is there any update ?

0 Karma

rmungonda
Engager

Is this still not possible? I am looking for similar functionality. Thanks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...