Splunk Search

How to convert tabular data to a specific format?

mnj1809
Path Finder

Hello,

I've the following tabular formatted data:

mnj1809_0-1669922038675.png

How can I achieve the following:

mnj1809_1-1669922122511.png

Thanks in advance for your help.

@ITWhisperer

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Like this

Your search...
| stats list(country) as country list(count) as count by category region
| eventstats sum(count) as byRegion by category region
| eventstats sum(byRegion) as byCategory by category
| table category region country count byRegion byCategory

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Like this

Your search...
| stats list(country) as country list(count) as count by category region
| eventstats sum(count) as byRegion by category region
| eventstats sum(byRegion) as byCategory by category
| table category region country count byRegion byCategory

mnj1809
Path Finder

Thanks for your prompt reply.
Sorry for the late reply as I was out of town. The solution is working fine for me.
@bowesmana 

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...