In Splunk, is there a way to format data that normally contains
user, month-year, hits, clicks to display multiple values per column as seen in the screen shot below.
for example, if my data is:
User Month/Year Hits Clicks
user1 2017-01 1 2
user1 2017-02 3 4
user1 2017-03 5 6
user1 2017-04 7 8
user2 2017-01 9 10
user2 2017-02 11 12
user2 2017-03 1 2
user2 2017-04 4 6
I would like to have it automatically display Total Clicks and Total Hits per month/year (as columns containing hits and clicks) for each user (with user being displayed per row)
Splunk's table visualization doesn't support multi headers, so this may be the best workaround
your current search giving fields User,"Month/Year","Hits","Clicks"
| chart sum(Hits) as "Total Hits", sum(Clicks) as "Total Clicks" over User by "Month/Year"
Output columns will be like
User , Total Hits: 2017-01 , Total Clicks: 2017-01 , Total Hits: 2017-02 , Total Clicks: 2017-02....
Splunk's table visualization doesn't support multi headers, so this may be the best workaround
your current search giving fields User,"Month/Year","Hits","Clicks"
| chart sum(Hits) as "Total Hits", sum(Clicks) as "Total Clicks" over User by "Month/Year"
Output columns will be like
User , Total Hits: 2017-01 , Total Clicks: 2017-01 , Total Hits: 2017-02 , Total Clicks: 2017-02....