Hi I have some events in splunk which are of this form-
Location: some value(same value can be there in multiple events)
Client: some value(same value can be there in multiple events)
TransactionNumber: some value(Unique for each event)
Transaction Time: some value(Unique for each event)
Now I want a table in this form -
Basically each location can have multiple clients and each client can have different transactions. Transaction number and transaction time are unique and have one to one mapping.
I am using this query in splunk-
| stats list(TransactionNumber) list(TransactionTime) by Location Client
What's happening is I am getting unique combination of location and client but what I want is unique clients to be listed against a particular Location.
This is what i am getting-
How can the query be modified to achieve the same?
Here is a complete example using the _internal index
For your use-case I think this should work
If this fixes your problem, take a moment to accept the answer. This can be done by clicking on the check mark beside the answer to toggle it from greyed out to filled in!
Cheers