Hi,
I have the following query:
index=src | stats count by message
which gives me results as
message count
a1 10
a2 40
I want to run this query everyday and the results should be appended as a separate column per day as
message count count2
a1 10 23
a2 40 45
and I want the results to be in an excel sheet daily. Is it possible to do so in Splunk ?
thanks
pks
(search)
index=src| eval Date=strftime(_time, "%Y-%m-%d")|stats count by Date,message
(Result)
Date message count
2014-10-1 a1 10
2014-10-1 a2 40
2014-10-2 a1 23
(export csv)
Date message count
2014-10-1, a1, 10
2014-10-1, a2, 40
2014-10-2, a1, 23
(EXECL PIVOT TABLE)
Line : message
Column : Date
Value : count
message |2014-10-1 |2014-10-2
a1 |10 | 23
a2 |40 |45
You might benefit the app for Excel Export
https://apps.splunk.com/app/760/#/documentation
You might also benefit from using the outputcsv
command
http://docs.splunk.com/Documentation/Splunk/6.1.4/SearchReference/Outputcsv