Splunk Search

how to have a timechart table group by columns

muthvin
New Member

Hi,

Please help me in creating a table with timechart grouped by columns:
_time Products Service

ProductA ProductB ProductC ServiceD ServiceE ServiceF
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa
xxxx assaaa assaaa assaaa assaaa assaaa assaaa

Tags (2)
0 Karma

woodcock
Esteemed Legend

Very generally, like this:

... | timechart span=1d dc(*) values(*)

You can then trim back to use just the dc or values pieces that you need (I am not sure if you are counting or listing). Change 1d to whatever you need (this is 1 day).

0 Karma

nawneel
Communicator

Can you be please more specific with question ? is this your sample set of data ??

0 Karma

debanjankundu
Explorer

Can you please elaborate your quary to understand your question clearly

0 Karma

muthvin
New Member

I want a query to create a table with time stamp as column A
Products as column B and Services as Column C....then ColumnB (Products) should have 3 sub-column product A, B, c resp...like we use to have in Excel.

0 Karma

muthvin
New Member

Yes its just a sample data...

_time Products Services

ProductA Product B Product C ServiceA Service B Service C

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...