I have a table from a timechart like this :
Month LE11 LE12 LE41
January 1680 5218 1241
February 3949 3427 2850
March 3548 1307 6016
My goal is:
January February March
LE11 1680 3949 3548
LE12 5218 3427 1307
LE41 1241 2850 6016
I actually use a trick with rename to obtain correct columns names, but I think it makes my search longer (got 12 columns). I read on Splunk docs, there is a header_field option, but it seems like it doesn't work. I don't really understand how this option works.
Forgive my poor English, thanx a lot.
... View more