Splunk Search

How to make column values as headers in dashboard

rcndpatel
Loves-to-Learn

I have a table that looks like...
CUSTOMER ADDRESS CONTACT
A 10 A Road (111)-222-3334
30 C Road (222)333-4444
B 20 B Lane (111)-221-1122
40 D Circle (444)-444-2222

Now I want to us the CUSTOMER name as the header in the table so that it looks like

A


ADDRESS CONTACT
10 A Road (111)-222-3334
30 C Road (222)333-4444

B


20 B Lane (111)-221-1122
40 D Circle (444)-444-2222

0 Karma

to4kawa
Ultra Champion
<dashboard>
  <label>header test</label>
  <search id="baseSearch">
    <query>|makeresults 
| eval _raw="CUSTOMER,ADDRESS,CONTACT
A,10 A Road,(111)-222-3334
,30 C Road,(222)333-4444
B,20 B Lane,(111)-221-1122
,40 D Circle,(444)-444-2222"
| multikv forceheader=1
| table CUSTOMER,ADDRESS,CONTACT
| filldown</query>
    <earliest>0</earliest>
    <latest></latest>
    <sampleRatio>1</sampleRatio>
  </search>
  <row>
    <panel>
      <table>
        <title>A</title>
        <search base="baseSearch">
          <query>| where CUSTOMER="A"
            |table ADDRESS CONTACT</query>
        </search>
      </table>
    </panel>
    <panel>
      <table>
        <title>B</title>
        <search base="baseSearch">
          <query>| where CUSTOMER="B"
| table ADDRESS CONTACT</query>
        </search>
      </table>
    </panel>
  </row>
</dashboard>
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...