Splunk Search
Highlighted

Refer to a field in table by its position

Builder

Wondering if we can do something like this:

... | table * | sort by <1>

Where <1> refers to the first field in the table as the field names are dynamic and subject to change.

Tags (2)
0 Karma
Highlighted

Re: Refer to a field in table by its position

SplunkTrust
SplunkTrust

Try this

 | stats values(*) as * | sort 0 *
0 Karma
Highlighted

Re: Refer to a field in table by its position

Builder

Nope, this will group everything up in one cell which is not the desired outcome 🙂

0 Karma
Highlighted

Re: Refer to a field in table by its position

Champion

If the order of field names is acceptable

 ... | table * |sort [search (your search)|head 1 | table * | stats dc(*) as * | transpose |head 1|rename column as query]

View solution in original post

0 Karma
Highlighted

Re: Refer to a field in table by its position

Builder

Awesome, that worked. Can you please explain this?

| rename column as query
0 Karma
Highlighted

Re: Refer to a field in table by its position

Champion

The return value will be the value only. Usually field = value.

special field:query

index=* [inputlookup xxx.csv | fields cola]
->(col
a=1) OR (cola=2) OR (cola=3) ・・・・

index=* [inputlookup xxx.csv | rename col_a as query | fields query]
->(1) OR (2) OR (3) ・・・・

0 Karma