Splunk Search

How do I delete header with transpose?

jip31
Motivator

hello

I use a transpose command in order to have _time field displayed in column instead row

First question :

how to delete the header?

jip31_0-1647604765742.png

second question :

 

I was doing a color formatting like this

<format type="color" field="Qualité">
<colorPalette type="list">[#53A051,#F1813F,#DC4E41]</colorPalette>
<scale type="threshold">2,10</scale>
</format>

 

Since use transpose, the formatting doesnt works

what I have to do please?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Use header_field

transpose - Splunk Documentation

Remove  field="Qualité" so that the formatting applies to all fields

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Use header_field

transpose - Splunk Documentation

Remove  field="Qualité" so that the formatting applies to all fields

0 Karma

jip31
Motivator

I done header_field= Menu but I have always row1, row2....

0 Karma

yuanliu
SplunkTrust
SplunkTrust

@jip31 wrote:

I done header_field= Menu but I have always row1, row2....


This only means that "Menu" is not a column name in your original table.  You need to look at column "column", and decide which row should be used as header_field. (Very probably it is the first row .)

Look at the table from this sample search:

index=_internal
| chart count over log_level by sourcetype

Try the following three commands:

  1. | transpose
  2. | transpose header_field=log_level
  3. | transpose header_field=log_level column_name=sourcetype

You'll see how these options interact with the original table.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What is your full search?

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...