Hii,
I have a data in the Splunk table like the below image.
Arista ConsoleRule Host UnknownRule
| Passed | Failed | GDTVFVDFVS-BDHF | Passed |
| Passed | Failed | FSSGVDF-BDHF | Passed |
| Failed | DGUYSFDF-BDHF | Passed | |
| Passed | Failed | ||
| Failed | Failed | DGUYSFDF-BDHF | |
| Failed | Failed | DGUYSFDF-BDHF |
Needed like below image
AristaConsoleRuleHostUnknownRule
| Passed | Failed | GDTVFVDFVS-BDHF | Passed |
| Passed | Failed | FSSGVDF-BDHF | Passed |
| Failed | Failed | DGUYSFDF-BDHF | Passed |
| Passed | Failed | FSSGVDF-BDHF | |
| Failed | Failed | DGUYSFDF-BDHF | |
| Failed |
Can anyone Please Help us,
Is there any possible way to achive this.
What search have you used to create your table in the first place?
What criteria are you using to "move" the values up the table?
Your second table doesn't include the same values as the first table so it is a little difficult to determine what it is you are trying to do.