Splunk Search

how to display data with multiple column and row?

jasklee
Engager

I need to create a table which will display

workweek as rows

and subarea as column, meanwhile the data inside will display the passing percentage for each subarea for every workweek.

i tried

*|stats count(eval(status="Failed")) AS fail,count(eval(status="Passed")) AS pass by workweek|eval passPercentage=if(pass+fail== 0, "-",round(pass/(pass+fail)*100,2))|fields workweek,passPercentage

This will only calculate for overall passPercentage for each workweek, but i want it to be done with each subarea of each workweek...

my sample output will be like this

              subArea1 subArea2 subArea3...

workweek1 12 32 88

workweek2 96 45 12

workweek3 23 78 43

workweek4 37 79 98

Tags (4)
0 Karma

lguinn2
Legend

Try this

yoursearchhere
| stats count(eval(status="Failed")) as fail, count(eval(status="Passed")) as pass by workweek subArea
| eval passPercentage=if(pass+fail== 0, "-",round(pass/(pass+fail)*100,2))
| xyseries workweek subArea passPercentage
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...