Splunk Search

How do I change the output format of my search results?

SrinivasaC
Path Finder

Hi

Using the search below, I'm getting an output in the format below (A,B,C are headers):

A    B    C
------------------
46   23   34
46   23   45
46   23   67
46   56   26
46   56   48
46   56   16
56   12   21
56   12   43
56   12   54
98   29   67
98   29   98
98   29   64

But as per my client use, I need the output in the format below:

A      B      C
---------------------
46     23     34
              45
              67
46     56     26
              48
              16
---------------------
56     12     21
              43
              54
---------------------
98     29     67
              98
              64
---------------------

I have used stats, List, values, and transaction commands, but it didn't work.

Can I get any help?

Thanks in advance.

Tags (3)
0 Karma
1 Solution

woodcock
Esteemed Legend

This will do it:

 ... | stats list(C) AS C BY A B

View solution in original post

0 Karma

woodcock
Esteemed Legend

This will do it:

 ... | stats list(C) AS C BY A B
0 Karma

SrinivasaC
Path Finder

What if I need all columns would display under one column?
means in output A , B and C should merged into one column as "A".

0 Karma

woodcock
Esteemed Legend

Like this:

... | eval BandC = B . " " . C | stats values(BandC) AS "B C" by A
0 Karma

SrinivasaC
Path Finder

unable to format in html, last two rows would be display in "C" in each of the results.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...