Hi Splunk,
I have a table like below
Component Green Amber Red
Resp_time 0 200 400
5xx 0 50 100
4xx 0 50 100
I want to combine them to produce single row like below
Resp_time_Green Resp_time_Amber Resp_time_Red 5xx_Green 5xx_Amber 5xx_Red 4xx_Green 4xx_Amber 4xx_Red
0 200 400 0 50 100 0 50 100
| untable Component Level count
| eval Component_Level=Component."_".Level
| table Component_Level count
| transpose 0 header_field=Component_Level
| fields - column
Thanks! Works like a charm!
| untable Component Level count
| eval Component_Level=Component."_".Level
| table Component_Level count
| transpose 0 header_field=Component_Level
| fields - column