Splunk Search

Add column names to already existing column names

Chinmai
Explorer

Hello,

I have excel data as shown in the attached screenshot, I want to have same report in my splunk enterprise with same data.

Any one has any idea how to do this?

Thanks in advance.

Tags (1)
0 Karma

Masa
Splunk Employee
Splunk Employee

I've seen such tables as a result of "pivoting Data Frame".

Af far as I know,
if you're looking for the exact table format, Splunk does not ship built-in feature like that.

In Splunk's built-in table, if we really try to display such data, a table format would be as follows;

---------------+-----------------------------------------------------------------------------------------
Col01          | Main01:Sub01 | Main01:Sub02 | Main02:Sub01 | Main02:Sub02 | Main03:Sub01 | Main03:Sub02
---------------+-----------------------------------------------------------------------------------------
ACTUALS        | 
ACTUALS        | 
ACTUALS        | 
ACTUALS        | 
ASSUMPTIOIN    | 
ASSUMPTIOIN    | 
ASSUMPTIOIN    | 
ASSUMPTIOIN    | 
ASSUMPTIOIN    | 
ASSUMPTIOIN    | 
RECOMMENDATION |
RECOMMENDATION |
RECOMMENDATION |
RECOMMENDATION |
.....
0 Karma

Chinmai
Explorer

Thanks for your answer, but how to do this? or is there any way using table embedding?

0 Karma

Masa
Splunk Employee
Splunk Employee

Can you post several sample data, and real tables you're looking for based on the sample events?
Otherwise, I cannot tell if that's possible in your case. I was posing possible data format.

0 Karma

DalJeanis
Legend

Okay, your layout is a bit vague. There are a couple of ways to achieve this, but the exact method is going to depend on what kind of data is in each of those columns. Also, it will partly depend on whether columns 6 and 7 are the labels for the rows in each of the action/assumption/recommendation areas. Is there something secret or proprietary about the actual layout, or were you just trying to make the question generic?

0 Karma

Chinmai
Explorer

Hi Dal Jeanis,

Lets assume the data are numeric values and any one column has string value lets say col8.
Do you know any way to do this? I just want the same excel report in the splunk dashboard. that's all.
Can this be done with custom search command?

Many Thanks in advance:)

0 Karma

Chinmai
Explorer

This is just a generic question, col5 -col10 are the labels for data in each action/assumption/recommendation areas. col1-col3 are labels for col9-col10. The basic question here I am asking is how can I add column names to already existing column names. Like here, under col1, there should be col9 and col10. And under col2, there should be col9 and col10. How can I achieve this?

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...