Splunk Search

Using stats to organise repetitive data

leonheart78
Explorer

I have a set of data as below:
alt text

If you can see, the TagNames are repetitive. I would want to re-arrange it to below format

TagName LimitString1 LimitString2 LimitString3 .. . . . . . . . . .

CHEM_R13719 null 18
CHEM_R13720 null 01
.
.
CHEM_R13723 0 4940

May I know how can I use stats command to achieve this? Thank you

Tags (2)
0 Karma

utk123
Path Finder

It seems you are looking for something like this:
index=.... | stats list(LimitString) as "Limit String" by TagName

0 Karma

DalJeanis
Legend

Try...

 Your search
| eval LimitString=coalesce(LimitString,"")
| stats count by TagName LimitString
0 Karma

leonheart78
Explorer

Unfortunately, the output is not what I required. Basically, we need to sort the values in LimitString, into the respective TagName. I was reading up on the "bin" command, not sure it would help in getting what I wanted.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...