Splunk Search
Highlighted

Display data in a table based on fields.

New Member

I have 3 fields in my table.
Store_id Minutes Date
1234 40 07/06
1232 50 07/07
1234 60 07/07
1232 70 07/06

I want to display the data in following manner:

Store_iD 07/06 07/07
1234 40 50
1232 70 60

Where the table has Minutes displayed based on the date for each store.

Can you please provide the query.

0 Karma
Highlighted

Re: Display data in a table based on fields.

Path Finder

try this code:

<your base query> | table Store_id Minutes Date | chart values(Minutes) over Date by Store_id | transpose header_field=Date | rename column as Store_id
0 Karma
Highlighted

Re: Display data in a table based on fields.

Esteemed Legend

Like add this to the bottom:

... | xyseries Store_id Date Minutes

View solution in original post

0 Karma