Splunk Search

How to Move the table values to the top with query?

vinod743374
Communicator

Hii,

I have a data in the Splunk table like the below image.

    Arista     ConsoleRule          Host                    UnknownRule

Passed Failed GDTVFVDFVS-BDHF Passed
Passed Failed FSSGVDF-BDHF Passed
Failed   DGUYSFDF-BDHF Passed
Passed Failed    
Failed Failed DGUYSFDF-BDHF  
Failed Failed DGUYSFDF-BDHF  


Needed like below image 

AristaConsoleRuleHostUnknownRule

Passed Failed GDTVFVDFVS-BDHF Passed
Passed Failed FSSGVDF-BDHF Passed
Failed Failed DGUYSFDF-BDHF Passed
Passed Failed FSSGVDF-BDHF  
Failed Failed DGUYSFDF-BDHF  
Failed      

 


Can anyone Please Help us,
Is there any possible way to achive this.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @vinod743374,

could you share your search and a sample of your data?

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What search have you used to create your table in the first place?

What criteria are you using to "move" the values up the table?

Your second table doesn't include the same values as the first table so it is a little difficult to determine what it is you are trying to do.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...