Hi Team,
My single Event looks like below:
FYI...
USER PID %CPU %MEM COMMAND
daemon 6029500 0.2 0.0 .vasd
daemon 5963962 0.1 0.0 .vasd
auwasesp 13107344 0.0 1.0 java
auwasesp 12714040 0.0 3.0 java
auwasesp 12648618 0.0 0.0 java
auwasesp 12517388 0.0 1.0 java
auwasesp 12452016 0.0 1.0 java
ausassrv 13434928 0.0 0.0 sas
ausasadm 18022636 0.0 0.0 splunkd
ausasadm 16384182 0.0 0.0 splunkd
I want this to be in Stats table, so that i can create dashboard out of it.
space is the delimiter. Pleas help me here..!
Maybe you want to look at multikv as well. So something like
<yoursearch> | multikv | stats values(*) as * by PID
minor note - multikv assumes the table to be extracted is in the _raw field.
Here's a run-anywhere demo on the original poster's data...
| makeresults
| eval _raw ="blah garble anyoldstuff
USER PID %CPU %MEM COMMAND
daemon 6029500 0.2 0.0 .vasd
daemon 5963962 0.1 0.0 .vasd
auwasesp 13107344 0.0 1.0 java
auwasesp 12714040 0.0 3.0 java
auwasesp 12648618 0.0 0.0 java
auwasesp 12517388 0.0 1.0 java
auwasesp 12452016 0.0 1.0 java
ausassrv 13434928 0.0 0.0 sas
ausasadm 18022636 0.0 0.0 splunkd
ausasadm 16384182 0.0 0.0 splunkd"
| multikv
if fields are extracted, then use | table
your search | table USER PID %CPU %MEM COMMAND
if fields are not extracted, click an event -> event actions -> extract fields - > delimiters - > space - > name your fields -> save
now run the search above