Hi All;
I want my table to display only fields that have values for at least 1 row AND have the fields be in the order that I specify. Splunk always puts the fields in Alphabetical Order, which is not what I want. For example, here's my code:
...| chart count over global_stand_name by global_order_status_display
This gives me what i want by not including NULL values, but the ordering of the fields is off. Thus I do this:
| table Stand Created Bumped Assigned Completed
which gives me my data in the correct order but it then displays fields that might have no values in it. Thus my table will look like this:
Stand, Created, Bumped, Assigned, Completed
stand1, 5, , , 10
stand2, 6, , 12, 11
stand3, 7, , 2, 23
In this case there are no values for Bumped, so I'd like the field Bumped to not be displayed, but still have the order be Stand, Created, Assigned, Completed
Is this possible?
Thanks,
Tyler
... View more