Splunk Search

How can I transpose/transform data in multiple rows?

quahfamili
Path Finder

Hi all,

I was preparing my data to be visualised. However, I met with a challenge. The below is an extract of my data:

alt text

My desire output would be:

alt text

Note that the key value is dynamic, there could be 10 to 20 numbers of keys.
Anyone has any idea to achieve this?

Thanks in advance!

0 Karma
1 Solution

vnravikumar
Champion

Hi

Try this

your query... 
| table key,value,field1,field2 
| eval {key}=value 
| fields - key, value 
| table *

View solution in original post

vnravikumar
Champion

Hi

Try this

your query... 
| table key,value,field1,field2 
| eval {key}=value 
| fields - key, value 
| table *

quahfamili
Path Finder

Hi it works, 1 more question for {} how do i control the numbers of keys? it seems like defaulted at 24 columns.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...