Splunk Search

convert pivot table into stats

jeck11
Path Finder

Hi everyone,

I have a very basic search outputting two types of entries into a field called "event". I need to get a count of each type per hour. I've been able to get the view I want using the pivot but don't really want to burden the system maintaining the data model if I don't need to. So here's my question:


How can I create a table (assuming using stats) to show two rows (one for each type) and columns for each hour's total (descending)?

 

Desired format:
Desired format using pivotDesired format using pivot

Current output when I try to use stats: Current stats outputCurrent stats output

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval time=strftime(_time,"%Y-%m-%d %H:%M")
| xyseries event time count

View solution in original post

ajaynegi09
New Member

we are the leading waste collector for <a href="https://www.shaktiplasticinds.com/extended-producer-responsibility-epr"Extended producer responsibility </a> waste management

0 Karma

ajaynegi09
New Member

we are the leading waste collector for <a href="https://www.shaktiplasticinds.com/extended-producer-responsibility-epr"Extended producer responsibility </a> waste management

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval time=strftime(_time,"%Y-%m-%d %H:%M")
| xyseries event time count

jeck11
Path Finder

Worked perfectly. TY!

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...