Splunk Search

Table Column Headings

Sriram
Communicator

I am doing a search based on a pulldown values and displaying the results in a table. Here is the sample search
stats count(eval(val1)), count(eval(val2)) BY $viewby$, itemType | table $viewby$, "Item Type"

(where viewby is selected value from dropdown. Now the applicable values for viewby in the drop down are "type1", "type2", "type3". In the column header, I want to display "Type 1" for "type1". How can i do that. It is currently displaying "type1" as column header. rename command is not working as well. Appreciate your input.

Tags (2)
1 Solution

MHibbin
Influencer

sriramvaidhyanathan,

You could pipe to the rename command at the end of the search(Splunk docs here), for example:

<your_search>| rename type1 AS "Type 1",type2 AS "Type 2"

As can be seen above, you can do this multiple times with one "rename" command... simply seperate with a comma (i.e. ",")

Hope this helps,

MHibbin

P.s. if this answers your question, please mark the answer as accepted/upvote the answer.

View solution in original post

MHibbin
Influencer

sriramvaidhyanathan,

You could pipe to the rename command at the end of the search(Splunk docs here), for example:

<your_search>| rename type1 AS "Type 1",type2 AS "Type 2"

As can be seen above, you can do this multiple times with one "rename" command... simply seperate with a comma (i.e. ",")

Hope this helps,

MHibbin

P.s. if this answers your question, please mark the answer as accepted/upvote the answer.

andrewpense825
Explorer

I'm sure this has been asked to death but can I do this as an inline process during a table transforming command?

Tags (2)
0 Karma

Sriram
Communicator

I was doing rename prior to the table. Something like this. stats count(eval(val1)), count(eval(val2)) BY $viewby$, itemType | rename $viewby$ AS ....| table ..... Changed rename to pipe at the end. Works fine now. Thanks for the help !

0 Karma
Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...