Splunk Search

How can I take date Values as Column Names?

darshana2511
New Member

Hello ,

I am writing one query in Splunk to retrieve the events from a JSON log file. I am getting one value of a table as mentioned in image capture.png.

But I want to take date values as column names. Please refer to capture 1 image. Can you please help me as early as possible?

I look forward to hearing from you.

Thank you in advance.

alt text

alt text

0 Karma

FrankVl
Ultra Champion

A bit difficult without seeing the rest of your data / field names, but try something like this:

...your current search...
| chart Result over System by New_Date

Note: those merged cells like "Date" and "AD" cannot be done in splunk (well, not unless you go all out custom html/js in a dashboard, that is).

0 Karma

accsam
New Member

use the transpose command

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...