Hi,
I am trying to display some test results and by using following search string I am getting what I want:
… | chart count(eval(testStepStatus=="FAIL")) by Datum, systemIDPair
Here please see the attachment to get idea how it looks like:
http://i.imgur.com/Jhls1xO.jpg
But since the requirements have been changed, I need to put not the numbers in table cells but strings(hold in field resultString) like “1,1,0,-” so I should/would change search string into something like:
… | chart first(resultString) by Datum, systemIDPair
Where resultString can have some special character arrays like “1,1,0,-” or “1,0,0,1” or like this “-,-,-,-”.
So is it possible to create “Statistic-Tab-View" with Splunk chart function having in the cells such “strings” and not just numbers(string can give more information as just single number) ?
(Edited)
So for example if events in Splunk Index are following:
Datum resultString systemIDPair
01.012015 "1,1,0,-" "1/01"
01.012015 "1,0,0,1" "1/04"
01.012015 "-,-,-,-" "1/05"
02.012015 "0,1,0,-" "1/01"
02.012015 "0,0,0,1" "1/04"
02.012015 "0,-,-,-" "1/05"
...
I do expect table view as following:
http://i.imgur.com/7IC3fmu.jpg
Best regards,
Milan
... View more