Hello. I've got a problem.
I have a logfile.
And I would like to create a pivot table (url, referer) and export it to csv.
But there is one problem: some refs are empty.
Then splunk.... exports only these rows where ref is not empty. So, instead of including all rows, the exported CSV contains only ~5%,
How to fix it?
Thank you in advance for your help
I don't think the term "pivot table" is relevant. You just need a cross reference table. Try this...
your search that returns the records
| fields url referrer
| eval referrer=coalesce(referrer,"")
| stats count by url referrer
| fields - count