Splunk Search

How to list out the field in tabular format?

AL3Z
Builder

Hi All,

How do we list out the fields in tabular format..
Eg:

hostname  action  
windows     allowed
                        deny
                        accept

---------------->  
hostname    action

windows    allowed
windows    deny
windows    accept

in this way I need a search in tabular format 

Thanks..

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AL3Z,

sorry but I don't understand: do you want the first or the second?

anyway, for the first, you need something like this:

<your_search>
| stats values(action) AS action BY host

in the second you have

<your_search>
| stats count BY host action
| fields - count

if you also want the count it's a little more complicated:

<your_search>
| stats count BY host action
| eval column=action."|".count
| stats values(column) AS column BY host

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...