Splunk Search

Display data in a table based on fields.

nikita012
New Member

I have 3 fields in my table.
Store_id Minutes Date
1234 40 07/06
1232 50 07/07
1234 60 07/07
1232 70 07/06

I want to display the data in following manner:

Store_iD 07/06 07/07
1234 40 50
1232 70 60

Where the table has Minutes displayed based on the date for each store.

Can you please provide the query.

0 Karma
1 Solution

woodcock
Esteemed Legend

Like add this to the bottom:

... | xyseries Store_id Date Minutes

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like add this to the bottom:

... | xyseries Store_id Date Minutes
0 Karma

jitendragupta
Path Finder

try this code:

<your base query> | table Store_id Minutes Date | chart values(Minutes) over Date by Store_id | transpose header_field=Date | rename column as Store_id
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...