Hi Team,
I have a table in Splunk which is as below
Name Val1 Val2 Val3 Val4
abc YES No Yes No
xyz No Yes Yes No
pqr No Yes No No
mno Yes No Yes Yes
I want the result to be as count of yes & no
by Name
for all val1
val2
.... and it should look like below
Val Yes No
Val1 2 2
Val2 2 2
Val3 3 1
Val4 1 3
Can anyone please help me how can i proceed to get above output.
Add this:
| untable Name Val YesOrNo
| stats count(eval(match(YesOrNo,"(?i)yes"))) AS Yes count(eval(match(YesOrNo,"(?i)no"))) AS No BY Val
Add this:
| untable Name Val YesOrNo
| stats count(eval(match(YesOrNo,"(?i)yes"))) AS Yes count(eval(match(YesOrNo,"(?i)no"))) AS No BY Val
Fantastic, this is what i needed! I tried so many things, but it was untable
which came to rescue.
Thanks @woodcock for your quick answer.