Splunk® Enterprise

Dashboards and Visualizations

Acrobat logo Download manual as PDF

Splunk Enterprise version 7.0 is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Generate a table

To generate a table, write a search that includes a transforming command. From the Search page, run the search and select the Statistics tab to view and format the table.

You can use the table command in a search to specify the fields that the table includes or to change table column order.

Search examples

  • Transforming search
    This search uses the chart transforming command.

    index = _internal | chart avg(bytes) over sourcetype

    The search generates a table with two columns.
    HB Table Formats table Screenshot.png

  • Transforming search with the table command
    This search generates a table with action, host, and count columns.

    index = _internal | stats count by action, host

    Generate table example 1.png

    To change the columns that appear in the table or to change column order, add the table command to this search. For example, add | table host count to generate a table with only the host and count columns.

    index = _internal | stats count by action, host | table host count

    Generate table example 2.png

Table sparklines

Sparklines show data patterns or trends in a results set. To generate a table sparkline, usestats or chart with the sparkline function in a search.

Sparkline width is determined by default data binning. You can adjust data binning as a parameter of the sparkline command.

For more information, see Add Sparklines to your search results in the Search Manual.

Last modified on 21 February, 2018
Table visualization overview
Format table visualizations

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters