Splunk Search

How do I delete header with transpose?

jip31
Motivator

hello

I use a transpose command in order to have _time field displayed in column instead row

First question :

how to delete the header?

jip31_0-1647604765742.png

second question :

 

I was doing a color formatting like this

<format type="color" field="Qualité">
<colorPalette type="list">[#53A051,#F1813F,#DC4E41]</colorPalette>
<scale type="threshold">2,10</scale>
</format>

 

Since use transpose, the formatting doesnt works

what I have to do please?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Use header_field

transpose - Splunk Documentation

Remove  field="Qualité" so that the formatting applies to all fields

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Use header_field

transpose - Splunk Documentation

Remove  field="Qualité" so that the formatting applies to all fields

0 Karma

jip31
Motivator

I done header_field= Menu but I have always row1, row2....

0 Karma

yuanliu
SplunkTrust
SplunkTrust

@jip31 wrote:

I done header_field= Menu but I have always row1, row2....


This only means that "Menu" is not a column name in your original table.  You need to look at column "column", and decide which row should be used as header_field. (Very probably it is the first row .)

Look at the table from this sample search:

index=_internal
| chart count over log_level by sourcetype

Try the following three commands:

  1. | transpose
  2. | transpose header_field=log_level
  3. | transpose header_field=log_level column_name=sourcetype

You'll see how these options interact with the original table.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What is your full search?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...