Splunk Search

Table Column Headings

Sriram
Communicator

I am doing a search based on a pulldown values and displaying the results in a table. Here is the sample search
stats count(eval(val1)), count(eval(val2)) BY $viewby$, itemType | table $viewby$, "Item Type"

(where viewby is selected value from dropdown. Now the applicable values for viewby in the drop down are "type1", "type2", "type3". In the column header, I want to display "Type 1" for "type1". How can i do that. It is currently displaying "type1" as column header. rename command is not working as well. Appreciate your input.

Tags (2)
1 Solution

MHibbin
Influencer

sriramvaidhyanathan,

You could pipe to the rename command at the end of the search(Splunk docs here), for example:

<your_search>| rename type1 AS "Type 1",type2 AS "Type 2"

As can be seen above, you can do this multiple times with one "rename" command... simply seperate with a comma (i.e. ",")

Hope this helps,

MHibbin

P.s. if this answers your question, please mark the answer as accepted/upvote the answer.

View solution in original post

MHibbin
Influencer

sriramvaidhyanathan,

You could pipe to the rename command at the end of the search(Splunk docs here), for example:

<your_search>| rename type1 AS "Type 1",type2 AS "Type 2"

As can be seen above, you can do this multiple times with one "rename" command... simply seperate with a comma (i.e. ",")

Hope this helps,

MHibbin

P.s. if this answers your question, please mark the answer as accepted/upvote the answer.

Sriram
Communicator

I was doing rename prior to the table. Something like this. stats count(eval(val1)), count(eval(val2)) BY $viewby$, itemType | rename $viewby$ AS ....| table ..... Changed rename to pipe at the end. Works fine now. Thanks for the help !

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...