Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Transposing a table with _time as header and grouping the results

$
0
0
Hello all, I currently have a search that produces the following output: ![alt text][1] This is the result of multiple append and join columns. I would like to transpose the table to this: ![alt text][2] [1]: /storage/temp/275842-data.png [2]: /storage/temp/275843-data2.png I've tried to use `| transpose`, but I simply couldn't get it to appear the way I want it. The whole data for Level 1 disappears. Can anybody please point me in the right direction?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>