Splunk® Enterprise

Dashboards and Visualizations

Download manual as PDF

Download topic as PDF

Generate a table

To generate a table, write a search that includes a transforming command. From the Search page, run the search and select the Statistics tab to view and format the table.

You can use the table command in a search to specify the fields that the table includes or to change table column order.

Search examples

  • Transforming search
    This search uses the chart transforming command.

    index = _internal | chart avg(bytes) over sourcetype

    The search generates a table with two columns.
    HB Table Formats table Screenshot.png

  • Transforming search with the table command
    This search generates a table with action, host, and count columns.

    index = _internal | stats count by action, host

    Generate table example 1.png

    To change the columns that appear in the table or to change column order, add the table command to this search. For example, add | table host count to generate a table with only the host and count columns.

    index = _internal | stats count by action, host | table host count

    Generate table example 2.png

Table sparklines

Sparklines show data patterns or trends in a results set. To generate a table sparkline, usestats or chart with the sparkline function in a search.

Sparkline width is determined by default data binning. You can adjust data binning as a parameter of the sparkline command.

For more information, see Add Sparklines to your search results in the Search Manual.

PREVIOUS
Table visualization overview
  NEXT
Format table visualizations

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters