Reporting

How can I reformat this report?

GersonGarcia
Path Finder

All,

I have this search

 

 

 

index=sro sourcetype=sro-cosmo "DL Cert OK" "Security Posture End of sweep report" | extract pairdelim="\n" kvdelim=":" 
| rex field=_raw "--ticket \'(?<ticket>.+)\' --summary" | fillnull value=0 | table _time ticket SA_Fail_Total_Count SA_Success_Count SA_Unreachables LP_Firmware_too_old | dedup _time ticket

 

 

 

That results in:

Screenshot 2022-11-28 155908.png

But my user wants in this format:

Screenshot 2022-11-28 155835.png

I am using Splunk 8.2.6.

Is there any way to format this report? So my user does not need to manipulate it in Excel?

Thank you,

Gerson Garcia

0 Karma

yuanliu
SplunkTrust
SplunkTrust

You cannot get the mangled tabulation supported by many spreadsheets (because Splunk really only do tables, not pseudo tables), but this can be close visually:

index=sro sourcetype=sro-cosmo "DL Cert OK" "Security Posture End of sweep report"
| extract pairdelim="\n" kvdelim=":" 
| rex field=_raw "--ticket \'(?<ticket>.+)\' --summary"
| fillnull value=0
| table _time ticket SA_Fail_Total_Count SA_Success_Count SA_Unreachables LP_Firmware_too_old
| dedup _time ticket
| eval headings = mvappend(strftime(_time, "%m/%d/%Y %H:%M"), "SA_Fail_Total_Count", "SA_Success_Count", "SA_Unreachables", "LP_Firmware_too_old")
| eval values = mvappend(ticket, SA_Fail_Total_Count, SA_Success_Count, SA_Unreachables, LP_Firmware_too_old)
| foreach headings values
    [eval <<FIELD>> = mvjoin(<<FIELD>>, "
")]
| fields headings values

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...