Hi
I'm trying to group items by a specific field, and get all the values returned (i.e. without aggregation). I have the following:
I'm trying to convert that to:
I have tried
| chart values(value) by field
| transpose header_field=field
However the values(value) only selects unique values - I'm looking for all values.
Use list instead of values
| chart list(value) by field
| transpose header_field=field
However, this may not give quite what you want because you still have multi-value fields.
Assuming all fields are present for each set, you could try this
| streamstats count as row by field
| xyseries row field value