Splunk Search

Data format

ashu_g50
Path Finder

I have the data in this format where the value of the date_month changes how much data I select

date_month DATASET SUM

november HKG_generic 424

november PSE_generic 139

november ca_corp_zero 117

november corp_zero 10781

november ebz_europe 4104

november icm 132094

november mbs 586

november rm_agency 231

november rm_iso 586

november rm_strips 213

october HKG_generic 74

october PSE_generic 37

october ca_corp_zero 10

october corp_zero 1372

october ebz_europe 482

october icm 18329

october mbs 76

october rm_agency 29

october rm_iso 76

I want the output in this format :

DATASET November October September ..........

HKG_generic 424 74

PSE_generic 139 37

ca_corp_zero 117 10

corp_zero 10781 1372

ebz_europe 4104 482

icm 132094 18329

mbs 586 76

rm_agency 231 29

rm_iso 586 76

rm_strips 213

Tags (3)
0 Karma
1 Solution

ashu_g50
Path Finder
0 Karma

ashu_g50
Path Finder

I got it thanks

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...