Hi Folks,
I'm still new to Splunk queries. I'm struggling with the following (simple) table transformation:
Best to show as example. Here is my input:
status stage count
--------------------
FAIL dev 12
OK dev 14
FAIL prod 13
OK prod 34
FAIL prev 78
OK prev 23
Which I would like to transform to this:
stage OK FAIL
-----------------
dev 14 12
prev 23 78
prod 34 13
Help appreciated & Thanks!
Hi @mgutschelhofer
Try like
yoursearch |xyseries stage status count |stats values(OK) as OK values(FAIL) as FAIL by stage
Hi @mgutschelhofer
Try like
yoursearch |xyseries stage status count |stats values(OK) as OK values(FAIL) as FAIL by stage
Excellent, this did the job!
Many Thanks, Martin
Welcome 🙂