Hello, I wonder if somebody can please help me to sort the following data:
Into this table:
Any ideas are welcome
I was trying to run this query but it is not separating the values of the fields properly:
index=query_mcc | eval data = split(_raw, ",") | eval Date = strftime(_time, "%Y-%m-%d-%H:%M:%S") | eval Category = mvindex(data, 1) | eval Status = mvindex(data, -1) | eval Command = mvindex(data, 0) | table host, Date, Category, Status, Command
but is giving me this , where it only shows the first line..
Regardless of splitting the event, there is no "merged" cells in Splunk. So you can't visualize it this way.
index=query_mcc
| eval data=split(_raw,"
")
| mvexpand data
| eval data = split(data, ",")
| eval Date = strftime(_time, "%Y-%m-%d-%H:%M:%S")
| eval Category = mvindex(data, 1)
| eval Status = mvindex(data, -1)
| eval Command = mvindex(data, 0)
| table host, Date, Category, Status, Command