Splunk Search

How to convert Table of 16X1 to table 4X4?

thatsabhijeet
Explorer

I have a table of applications like this,

image 1.JPG 

How can I display the table like in below image,

image 2.JPG

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults
| eval "Application Name"=split("Pudge|Invoker|Juggernaut|Medusa|Crystal Maiden|Gyrocopter|Shadow Shaman|Spirit Breaker|Nyx Assasin|Lycanthrope|Chen|Nature Prophet|Faceless Void|Alchemist|Phantom Lancer","|")
| mvexpand "Application Name"
| fields - _time
| streamstats count as row 
| eval col=(row-1)%4
| stats list("Application Name") as "Application Name" by col
| transpose 0
| where column="Application Name"
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...