Splunk Search

How to format dynamic columns output after transpose?

bj6192
Explorer

Hi All,
We use transpose to display our result like below sample;
item 2017/11/01 2017/11/02 2017....
a 10000.01 20000.1 ....
b 300.05 5000.1 .....

We need show the result like this;
item 2017/11/01 2017/11/02 2017....
a 10,000 20,000 ....
b 300 5,000 .....

And when we format the result before the transpose command, the output after
transpose will return the original output. Does any command or method to meet
our require?
Thank You.

Tags (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI

Can you please try below function to format count.

YOUR_SEARCh | eval YOUR_NUMERIC_VALUE=tostring(YOUR_NUMERIC_VALUE, "commas") | transpose

Thanks

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI

Can you please try below function to format count.

YOUR_SEARCh | eval YOUR_NUMERIC_VALUE=tostring(YOUR_NUMERIC_VALUE, "commas") | transpose

Thanks

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi @bj6192,

Have you found your answer?

0 Karma

bj6192
Explorer

Thank you. It work now.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...