Hey all,
I've just encountered the pivot command for the first time and after reading through the Splunk page on it, I am still confused as to what it does. If it helps, here is my search q...
My problem is nearly identical to the issue listed in this past post (https://answers.splunk.com/answers/508577/pivot-not-showing-results-even-though-sampling-the.html) (not enough Karma to post l...
I have to use a root search in a pivot due to needing to join another data type. Is there a way to get _time to extract as Time? I have setup an eval in the pivot to extract the _time field but it w...
I have an SPL query that produces a table output like this:
ExtractStart ExtractEnd CM CallCount
12/12/2019 4:00 12/12/2019 4:15 CM2 55
12/12/2019 4:00 12/12/2019 4:15 CE1 0
12/12/20...
I have a pivot set up as follows:
Data source myfirewall
Rows split on source_ip
Columns include bytes_downloaded and outside_hosts .
I'd like to only return the top say 5...
Hi all, I have a pivot that changes the number of columns based on a drop-down selection. The first two columns remain consistent however the remaining columns can change (1st e.g. has 6...
I have a number of sources where I extract fields using CSV on report level.
Do pivots and datamodels only work with fields extract at transform level?
I have a pivot query that produces a one-million row table with ~50 columns. I'd like to extend the limit for that table to at least 10-million rows, but pivot tables can't do this.
To deal with t...