Reporting

Pivot vs. Search

spotter
New Member

So this is probably me not understanding how pivot works, but I am trying to build a pivot table, but it comes back with 0 results. If I click the 0 in the statistic table view of the create new pivot it takes me to a search view which clearly has results.

Am I misunderstanding how pivot is supposed to work? If the underlying search has results, why does the pivot show 0? especially when all I'm trying is for a basic count.

Tags (1)
0 Karma

rcorbisier_splu
Splunk Employee
Splunk Employee

If you haven’t seen it yet, you might want to check out the Splunk reference app with associated developer guidance that was built by a Splunk dev team. The current version covers app development topics from getting your data into Splunk Enterprise to building custom reporting through testing and packaging your app. There’s code and tests you can use and the development process is fully documented. The book is available in both paperback and Mobi from Amazon.

This is an ongoing dev effort by the team so check back often to see what’s been added. Also, feel free to post requests for future improvements and even contribute by reporting bugs or submitting pull requests.

0 Karma

jtrucks
Splunk Employee
Splunk Employee

This can't be answered without more specific information. What is in the data model? What is the search underlying the Pivot search you see when you click through to open it in search? What do you expect to happen? How are you trying to visualize the Pivot in a chart or table? If a chart, what kind? Are you trying the wrong kind of chart for the type of results you have (multi-modal results but using a single result chart style)?

Please give us more to work with so we can have enough information to help you find a solution.

--
Jesse Trucks
Minister of Magic
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...