Hi @DaveAsh
Would you be able to use the reverse command to get what you need? You can try adding it to the end of your search like so:
... | reverse
Here's the documentation on the reverse command:
http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Reverse
Ahh I see what you mean. I'm not very familiar with the Timewrap app as I haven't used it myself, but from looking at the images of the app on apps.splunk.com, you want to change the order of the legend on the right side?
Thank you ppablo, While I tried reverse it doesn't do what I need. It does reverse the week, but the lay out is still the same. Lets say the colors returned from timewrap are blue-this week, yellow-last week, red-2 weeks ago, purple-3 weeks ago. I would like the results to be purple-3 weeks ago, red-2 weeks ago, yellow- last week, and blue- this week. Just changing the order of the weeks.
Does that make any better sense? Thanks.