Splunk Search

How to pivot convert in Splunk?

zoe
Path Finder

Hi, 

I habe a table after using stats:

| stats values(durationSum) as duration by Fauf Station. How can I convert it to a table with only one line in such a format:

Fauf duration_Station1 duration_Station2, duration_Station7, duration_Station10

zoe_0-1658220188640.png

Thanks for helping in advance!

 

 

Labels (3)
0 Karma
1 Solution

zoe
Path Finder
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| xyseries Fauf Station duration
0 Karma

zoe
Path Finder

Thank! it helps!

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

 Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research Team (STRT) and ...