Splunk Search

Expand column in to rows

teewenjie22
Engager

How to Convert 

_time             ColumnA                  ColumnB 
timeA             10                                20

into 

_time             Fields           Value
TimeA            ColumnA    10
TimeA            ColumnB    20

Labels (2)
0 Karma
1 Solution

tread_splunk
Splunk Employee
Splunk Employee
index=_internal 
| timechart count span=1h by sourcetype limit=5 useother=f partial=f 
| untable _time sourcetype count

The first 2 lines are to create some data.  You want the untable command in line 3.  Super useful!  (Coupled with xyseries to do the reverse).

View solution in original post

0 Karma

tread_splunk
Splunk Employee
Splunk Employee
index=_internal 
| timechart count span=1h by sourcetype limit=5 useother=f partial=f 
| untable _time sourcetype count

The first 2 lines are to create some data.  You want the untable command in line 3.  Super useful!  (Coupled with xyseries to do the reverse).

0 Karma

teewenjie22
Engager

Thanks you So much

Tags (1)
0 Karma

tread_splunk
Splunk Employee
Splunk Employee
index=_internal 
| timechart count span=1h by sourcetype limit=5 useother=f partial=f 
| untable _time fields value

This might make things clearer.  You can use any value you like where I've used _time, fields & value for the new column headings / field names.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...