Hii,
I have a data in the Splunk table like the below image.
Arista ConsoleRule Host UnknownRule
Passed | Failed | GDTVFVDFVS-BDHF | Passed |
Passed | Failed | FSSGVDF-BDHF | Passed |
Failed | DGUYSFDF-BDHF | Passed | |
Passed | Failed | ||
Failed | Failed | DGUYSFDF-BDHF | |
Failed | Failed | DGUYSFDF-BDHF |
Needed like below image
AristaConsoleRuleHostUnknownRule
Passed | Failed | GDTVFVDFVS-BDHF | Passed |
Passed | Failed | FSSGVDF-BDHF | Passed |
Failed | Failed | DGUYSFDF-BDHF | Passed |
Passed | Failed | FSSGVDF-BDHF | |
Failed | Failed | DGUYSFDF-BDHF | |
Failed |
Can anyone Please Help us,
Is there any possible way to achive this.
What search have you used to create your table in the first place?
What criteria are you using to "move" the values up the table?
Your second table doesn't include the same values as the first table so it is a little difficult to determine what it is you are trying to do.