I have a search query that gives me data as
--------------------------------------------------
| {applicationid: app_1 |
| data_type: data_A |
| message: message_123 |
| } |
---------------------------------------------------
| {applicationid: app_2 |
| data_type: data_A |
| message: message_456 |
| } |
-------------------------------------------------
but I need to put this in splunk dash board as
-----------------------------------------------------
|data_type| Applicationid=app_1| Applicationid=app_2|
-----------------------------------------------------
|data_A | message_123 | message_456 |
|... | ... | .... |
---------------------------------------------------
Hi ,
try something like this:
| extract pairdelim="\r\n" kvdelim=":" | chart values(message) over data_type by applicationid
Hi ,
try something like this:
| extract pairdelim="\r\n" kvdelim=":" | chart values(message) over data_type by applicationid
Seems it works Thanks
In event
The data you are getting from search query giving result in table format or that is single event in example?
I’m getting In event