Splunk Search

How can we print results by 2 fields and group by another field

Naaba
New Member

Hi,
I have datas with these fields (this is a sample)

Project : Splunky
Label : Integration
Month : January

Project : Splunky
Label : Preproduction
Month : January

Project : Splunky
Label : Production
Month : April

Project : Mail
Label : Production
Month : February

Project : Share
Label : Integration
Month : March

Project : Share
Label : Production
Month : June

I want to print the results by Project by Month group by label

alt text

Is it possible?

Thanks

0 Karma

woodcock
Esteemed Legend

This sets up the sample data:

| makeresults
| eval raw="Project : Splunky, Label : Integration, Month : January::Project : Splunky, Label : Preproduction, Month : January::Project : Splunky, Label : Production, Month : April::Project : Mail, Label : Production, Month : February::Project : Share, Label : Integration, Month : March::Project : Share, Label : Production, Month : June"
| makemv delim="::" raw
| mvexpand raw
| rename raw AS _raw
| rex "Project\s*:\s*(?<Project>[^,]+),\s*Label\s*:\s*(?<Label>[^,]+),\s*Month\s*:\s*(?<Month>.*)"

This does the work that you need:

| eval _time = strptime(Month . "/1", "%b/%d")
| sort 0 _time
| streamstats dc(_time) AS _serial
| eval Month = case((_serial==1),                   Month,
                    (_serial==2),             " " . Month,
                    (_serial==3),            "  " . Month,
                    (_serial==4),          "   "  . Month,
                    (_serial==5),          "    " . Month,
                    (_serial==6),         "     " . Month,
                    (_serial==7),        "      " . Month,
                    (_serial==8),       "       " . Month,
                    (_serial==9),      "        " . Month,
                    (_serial==10),    "         " . Month,
                    (_serial==11),   "          " . Month,
                    (_serial==12),  "           " . Month,
                    (_serial==13), "            " . Month)
| chart values(Label) OVER Project BY Month
0 Karma

woodcock
Esteemed Legend

Like this:

Your Base Search Here .. | chart count OVER Project BY Month
0 Karma

Naaba
New Member

With this command I don't have the Label in the cells.
I have projets and months but not labels.
How can I add labels in cells?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...