Splunk Search

how to have a timechart table group by columns

muthvin
New Member

Hi,

Please help me in creating a table with timechart grouped by columns:
_time Products Service

ProductA ProductB ProductC ServiceD ServiceE ServiceF
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa

Tags (2)
0 Karma

woodcock
Esteemed Legend

Very generally, like this:

... | timechart span=1d dc(*) values(*)

You can then trim back to use just the dc or values pieces that you need (I am not sure if you are counting or listing). Change 1d to whatever you need (this is 1 day).

0 Karma

nawneel
Communicator

Can you be please more specific with question ? is this your sample set of data ??

0 Karma

debanjankundu
Explorer

Can you please elaborate your quary to understand your question clearly

0 Karma

muthvin
New Member

I want a query to create a table with time stamp as column A
Products as column B and Services as Column C....then ColumnB (Products) should have 3 sub-column product A, B, c resp...like we use to have in Excel.

0 Karma

muthvin
New Member

Yes its just a sample data...

_time Products Services

ProductA Product B Product C ServiceA Service B Service C

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...