Splunk Search

Display trellis based on rows

Azwaliyana
Path Finder

This serach result will always return 3 rows. I want display all row but in trellis. 

For the first row, it is the memory utilization for CIC-1

For the second row, it is the memory utilization for CIC-2

For the third row, it is the memory utilization for CIC-3

How can I do the trellis to display based on rows?

Do I need to add new column "Name" and insert CIC-1, CIC-2, CIC-3 to respective rows?

 

Azwaliyana_0-1640145638333.png

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi 

You could do it like this:

| makeresults 
| eval _raw="Name count
CIC-1 59
CIC-2 63
CIC-3 53"
| multikv forceheader=1
``` previous spteps genereates sample data based on your example ```
| stats sum(count) as count by Name

Also table Name, count should be ok for your last step, but definitely you are needing key + value for trellis (https://docs.splunk.com/Documentation/Splunk/8.2.3/Viz/VisualizationTrellis)

Then select "Single value" for visualization and aggregate it by Name (not with count) when you are selecting Trellis.

isoutamo_0-1640163927089.png

 

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...