Splunk Search

How to Move the table values to the top with query?

vinod743374
Communicator

Hii,

I have a data in the Splunk table like the below image.

    Arista     ConsoleRule          Host                    UnknownRule

Passed Failed GDTVFVDFVS-BDHF Passed
Passed Failed FSSGVDF-BDHF Passed
Failed   DGUYSFDF-BDHF Passed
Passed Failed    
Failed Failed DGUYSFDF-BDHF  
Failed Failed DGUYSFDF-BDHF  


Needed like below image 

AristaConsoleRuleHostUnknownRule

Passed Failed GDTVFVDFVS-BDHF Passed
Passed Failed FSSGVDF-BDHF Passed
Failed Failed DGUYSFDF-BDHF Passed
Passed Failed FSSGVDF-BDHF  
Failed Failed DGUYSFDF-BDHF  
Failed      

 


Can anyone Please Help us,
Is there any possible way to achive this.

0 Karma

gcusello
Legend

Hi @vinod743374,

could you share your search and a sample of your data?

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What search have you used to create your table in the first place?

What criteria are you using to "move" the values up the table?

Your second table doesn't include the same values as the first table so it is a little difficult to determine what it is you are trying to do.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...