Splunk Search

How to create custom results?

msalghamdi
Explorer

Dear Splunker,

 

i need you help in creating custom results to include in a report and output it in a table for statistics, here are the data:

 

msalghamdi_1-1686474929463.png

 

Thanks in advance

 

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just use makeresults to generate a block of text, then use multikv to split it into single rows/cols. If you want to add this to an existing report, use append.

But most probably it wil not make much sense if your report has other columns - it will not be a separate "legend" to the table. For that you'd have to create a dashboard with separate widgets - one for table, one for the legend (here you could probably just use static text)

0 Karma

msalghamdi
Explorer

thanks for the answer, the thing is whenever i create results, the same fields gets overwritten when i create multiple of it, please if you can create a search that would show it in a table id be thankful

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...