Splunk Search

Sort record based on the time field within the record (not the system time)

ishugupta
Path Finder

Hello,
I have my data in the below format :
314 888 abcd 98 2013-07-09-08.01.41.00
514 888 abcd 98 2013-07-07-08.01.42.00
364 888 abcd 98 2013-01-02-10.01.46.00
394 888 abcd 98 2013-07-02-11.01.48.00

I am trying to sort my records based on the 5th column time stamp (which is not the ingestion time stamp) .
Can you please help me with it?

Tags (2)
0 Karma

lguinn2
Legend

Hopefully, you have created the appropriate fields for your data. For the answer below, I assume that the 5th field is called timestamp

yoursearchhere
| eval ts = strftime(timestamp,"%Y-%m-%d-%H.%M.%S.%2N")
| sort ts

ishugupta
Path Finder

Thanks lguinn ...it works 🙂

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...