Splunk Search

Sorting Months in a Field

henryt1
Path Finder

So I wasn't really sure how to do this after reading the documentation, but I'm running the following search:

(host="web01.x.com") AND (source="/common/site-logs/x-activity.log") AND ("create" AND "project") NOT ("brief" OR "campaign" OR "proposal" OR "talentlist" OR "teamroom" OR "view" OR "criteria" OR "problem") | stats count by date_month

I get the data back that I want, however the months are in alphabetical order instead of by date. How can I sort these to be in date order with how they would go on a calendar?

Thanks in advance.

-Tyler

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

don't use the date_month field. They are unreliable. use

... | bucket _time span=1mon | stats count by _time

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

don't use the date_month field. They are unreliable. use

... | bucket _time span=1mon | stats count by _time
0 Karma

henryt1
Path Finder

Great! Thank you!

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...