Splunk Search

Table Column Headings

Sriram
Communicator

I am doing a search based on a pulldown values and displaying the results in a table. Here is the sample search
stats count(eval(val1)), count(eval(val2)) BY $viewby$, itemType | table $viewby$, "Item Type"

(where viewby is selected value from dropdown. Now the applicable values for viewby in the drop down are "type1", "type2", "type3". In the column header, I want to display "Type 1" for "type1". How can i do that. It is currently displaying "type1" as column header. rename command is not working as well. Appreciate your input.

Tags (2)
1 Solution

MHibbin
Influencer

sriramvaidhyanathan,

You could pipe to the rename command at the end of the search(Splunk docs here), for example:

<your_search>| rename type1 AS "Type 1",type2 AS "Type 2"

As can be seen above, you can do this multiple times with one "rename" command... simply seperate with a comma (i.e. ",")

Hope this helps,

MHibbin

P.s. if this answers your question, please mark the answer as accepted/upvote the answer.

View solution in original post

MHibbin
Influencer

sriramvaidhyanathan,

You could pipe to the rename command at the end of the search(Splunk docs here), for example:

<your_search>| rename type1 AS "Type 1",type2 AS "Type 2"

As can be seen above, you can do this multiple times with one "rename" command... simply seperate with a comma (i.e. ",")

Hope this helps,

MHibbin

P.s. if this answers your question, please mark the answer as accepted/upvote the answer.

andrewpense825
Explorer

I'm sure this has been asked to death but can I do this as an inline process during a table transforming command?

Tags (2)
0 Karma

Sriram
Communicator

I was doing rename prior to the table. Something like this. stats count(eval(val1)), count(eval(val2)) BY $viewby$, itemType | rename $viewby$ AS ....| table ..... Changed rename to pipe at the end. Works fine now. Thanks for the help !

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...