Hi @Edwin1471,
can you share the search you used to have those data?
Anyway, you could use the transpose command (https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Transpose).
putting attention to the options.
Ciao.
Giuseppe
| transpose 0 header_field=Process column_name=Process
To follow up,
How can I sort a table by column values, instead of rows after transposing it ?
I am not sure I understand what you are trying to do - the sort command will sort the events (rows) by values in the fields (columns) - can you give an example of what you are trying to achieve?