I have a table from a timechart like this :
Month LE11 LE12 LE41
January 1680 5218 1241
February 3949 3427 2850
March 3548 1307 6016
My goal is:
January February March
LE11 1680 3949 3548
LE12 5218 3427 1307
LE41 1241 2850 6016
I actually use a trick with rename to obtain correct columns names, but I think it makes my search longer (got 12 columns). I read on Splunk docs, there is a header_field option, but it seems like it doesn't work. I don't really understand how this option works.
Forgive my poor English, thanx a lot.
Have you looked at untable
and xyseries
commands. You can achieve what you are looking for with these two commands
this link can help you Mr splk_clheureux
https://answers.splunk.com/answers/241080/how-to-rotate-a-table-using-transpose-remove-the-f.html
Have you looked at untable
and xyseries
commands. You can achieve what you are looking for with these two commands
Thank you but I tried these two commands and the problem is that they do not show the columns with values 0 or empty
This is work. Thank you
Hi splk_clheureux,
The header_field option is actually meant to specify which field you would like to make your header field. For example, you are transposing your table such that the months are now the headers (or column names), when they were previously LE11, LE12, etc..
However, there may be a way to rename earlier in your search string. This depends on which commands you are using. Hope this helps!
Thank you for answer, I tried to use this option by setting header field=month but it doesn't work.