Splunk Search

How to convert Table of 16X1 to table 4X4?

thatsabhijeet
Explorer

I have a table of applications like this,

image 1.JPG 

How can I display the table like in below image,

image 2.JPG

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults
| eval "Application Name"=split("Pudge|Invoker|Juggernaut|Medusa|Crystal Maiden|Gyrocopter|Shadow Shaman|Spirit Breaker|Nyx Assasin|Lycanthrope|Chen|Nature Prophet|Faceless Void|Alchemist|Phantom Lancer","|")
| mvexpand "Application Name"
| fields - _time
| streamstats count as row 
| eval col=(row-1)%4
| stats list("Application Name") as "Application Name" by col
| transpose 0
| where column="Application Name"
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...