Splunk Search

How to display the values in search result as fields?

cycheng
Path Finder

I have a search which return below results:

status      total_user
passed      7
failed      3
unknown     14

How can I change the table so that it can display like this:

passed     failed    unknown    total
  7          3         14         24

I tried this but it is not working:
stats values(eval(status="passed")) AS passed values(eval(status="failed")) AS failed values(eval(status="unknown")) AS unknown sum(total_user) AS Total

Tags (1)
0 Karma

Gilberto_Castil
Splunk Employee
Splunk Employee

Add this at the end of your original search string. I will format the data in the desired format.

... | eval dummy=" " | xyseries dummy status total_user | fields - dummy | addtotals

I hope this helps.

cycheng
Path Finder

Thanks! It solved my problem. 🙂

0 Karma

woodcock
Esteemed Legend

Then you should come back and click Accept to close the question, @cycheng.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...