Splunk Search

Display trellis based on rows

Azwaliyana
Path Finder

This serach result will always return 3 rows. I want display all row but in trellis. 

For the first row, it is the memory utilization for CIC-1

For the second row, it is the memory utilization for CIC-2

For the third row, it is the memory utilization for CIC-3

How can I do the trellis to display based on rows?

Do I need to add new column "Name" and insert CIC-1, CIC-2, CIC-3 to respective rows?

 

Azwaliyana_0-1640145638333.png

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi 

You could do it like this:

| makeresults 
| eval _raw="Name count
CIC-1 59
CIC-2 63
CIC-3 53"
| multikv forceheader=1
``` previous spteps genereates sample data based on your example ```
| stats sum(count) as count by Name

Also table Name, count should be ok for your last step, but definitely you are needing key + value for trellis (https://docs.splunk.com/Documentation/Splunk/8.2.3/Viz/VisualizationTrellis)

Then select "Single value" for visualization and aggregate it by Name (not with count) when you are selecting Trellis.

isoutamo_0-1640163927089.png

 

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...