Hello,
Please help me with this.
I have result of two columns:
Tag-Key                                Tag-Value
Account                                   CIP
ApplicationName                   Infrastructure
AssetDataStored               InternalUseOnly
CostCenter                            Landing Zone
Environment                           LandingZoneStackSet
Name                                      Production
Owner                                     S3 LZ Access Logs
My question is, how do I parse them into individual columns like filter by Key:
Account                   ApplicationName          CostCenter          
CIP                            Infrastructure                Landing Zone
Sandbox                  Production                     CIP
etc                                                                     etc 
i tested and is not working good 😞 .,,Not working guys 😞 . I have other fields not only Tag-Key & Tag Value . I need to split that Tag-Key to be the column name , and Value to be the value for the columns ( and i have multiple values not only one) , but the other columns that i have ( region , aws_account_id etc ) to remain unchanged , and transpose is not good solution.
 
					
				
		
Hi @braicu
Try this
your query.. | sort Tag_Key,Tag_Value | table Tag_Key,Tag_Value | transpose 0  header_field=Tag_Key |fields - column
 
					
				
		
Ha! That was exactly my suggestion, but I tried testing it with makeresults and it didn’t work very well.
Maybe it will work with real data!?
 
					
				
		
It is working

I have tested and is not working 😞 . I have other columns not only those 2 and i need the other columns to remain unchanged. I need only tag-key to be parsed as column name , and tag-name to be the value for the columns.
 Anam
		
			Anam
		
		
		
		
		
		
		
		
	
			
		
		
			
					
		Hi braicu
Thank you for posting your question on the Splunk Answers community. Are you getting these results from a search? If possible can you include your search in your post so members of the community can help provide further guidance.
Thanks
 
					
				
		
Edited my post:
I was suggesting transpose, but on testing I'm not sure it will work for you.
Here is the documentation though: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Transpose
