Splunk Search

Help creating a specific kind of table layout

stjack99
Explorer

I'm trying to generate a table that is a count of things by the 12 months of the year. For instance, the chart might look like:

       |Jan|Feb|Mar|Apr|...|Dec| 
|Thing1| 15|102| 67|645|...|  0| 
|Thing2|  0| 17|111| 15|...|  8| 
|Thing3|  1|555|123|321|...|999| 
etc...

I've figured out how to do this my making the output verticle; count of things in a month, followed by the count of things in the next month and so on. I want to be able to stack the months horizontally.

Thanks in advance.

Tags (1)
0 Karma
1 Solution

steveyz
Splunk Employee
Splunk Employee
... | eval Month = strftime(_time, "%b") | chart count by Thing Month

View solution in original post

0 Karma

steveyz
Splunk Employee
Splunk Employee
... | eval Month = strftime(_time, "%b") | chart count by Thing Month
0 Karma

stjack99
Explorer

Thanks... I was way over thinking this...

0 Karma
Get Updates on the Splunk Community!

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...