Splunk Search

Table with Multiple by Fields

Ladron
New Member

I have a search that I have been asked to organize in a different way.

Mysearch | rex (FieldA)(FieldB)(FieldC)(FieldD) | chart latest(FieldD),FieldC by FieldB by FieldA

FieldD and FieldC have unique values

There will be multiple FieldD values for each FieldB and multiple FieldB values for FieldA

That will be for the full list, at some point I have been asked to do a relation for the top values of FieldD compared to FieldB as well.

I am a bit lost as to how to proceed with this.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The chart command allows only a single by clause.
Please share the desired output.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...