I think tableau works fine as per above image, if you want to see that results same like Splunk results, you can get that in the reporting level.
Please see below images.
In the data source it all ways detail values how ever in the reporting it was aggregating based on date or which even aggregation levels in your data.
can you please attched with mock data that would be good to solve your issue.
Apologies as I should've included the screenshot from the reporting level in that the only risk listed is WS.Reputation.1, but I changed the Splunk report to only return risk name, count, and month as why not let Tableau do the heavy lifting. So I now have this:
I connect and bing that into Tableau - how would I now go about creating a Top 10 Risk Name report by Month layout?
Awesome - thx so much!