I have just used .....chart count by env |addcolstotals |fillnull value="Total" env In my query
Its actually giving result as:
env Count
POD1 5
POD2 2
POD3 3
Total 10
I want it to be like
POD1 POD2 POD3 Total
5 2 3 10
I used transpose command but its giving result like:
column row1 row2 row 3
env POD1 POD2 POD3
Count 5 2 3
Is it possible to make "POD1" POD2 as table header instead of row 1, row 2 etc.
Please help me with this .
hi AdixitSplunk,
use header_field=env
in your transpose command.
see https://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Transpose
Bye.
Giuseppe
hi AdixitSplunk,
use header_field=env
in your transpose command.
see https://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Transpose
Bye.
Giuseppe
Jeez you're making this too easy 🙂
Fantastic 🙂
Does this give you what you're after?
...stats count by env |eventstats sum(count) as total |fillnull value="Total" env | chart limit=0 values(count) over total by host