Hello ,
I am writing one query in Splunk to retrieve the events from a JSON log file. I am getting one value of a table as mentioned in image capture.png.
But I want to take date values as column names. Please refer to capture 1 image. Can you please help me as early as possible?
I look forward to hearing from you.
Thank you in advance.
A bit difficult without seeing the rest of your data / field names, but try something like this:
...your current search...
| chart Result over System by New_Date
Note: those merged cells like "Date" and "AD" cannot be done in splunk (well, not unless you go all out custom html/js in a dashboard, that is).
use the transpose command