Splunk Search

Timechart's Table Column Header - Sorted in Descending Order

syslogap
New Member

Hi,

I'm using version 4.2.2 with the search query:

host = "JA8*" AND eventtype="firewall*" earliest=7/1/2011:0:0:0 | dedup _raw | timechart count by host span=month limit=20 

This produces a timechart with the table header sorted in descending order - "time, JA827J, JA826J, JA825J, JA822J, JA812A, JA810A, ...". Is there anything I can do to get the table header sorted in ascending order - "_time, JA810A, JA812A, JA822J, JA825J, ..." besides upgrading to 5.0 where this issue doesn't occur?

It appears descending order is being caused by using "limit" in the search query. I have more than 10 hosts so not using "limit" isn't an option as far as I understand it.

Thanks in advance for any help.

JForhan

Tags (1)
0 Karma

yong_ly
Path Finder

have you tried the sort command?

host = "JA8*" AND eventtype="firewall*" earliest=7/1/2011:0:0:0 | dedup _raw | timechart count by host span=month limit=20 | sort by host DESC

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

sort sorts rows, not columns.

0 Karma

syslogap
New Member

Thanks. That suffices as a work-around until we upgrade.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can specify the field order with the fields command, it might just require listing every field name.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...