Hi, I'm new on Splunk and I need to understand how to do this simple sort:
IP Value
192.168.0.1 1
192.168.0.2 5
192.168.0.2 3
192.168.0.1 2
192.168.0.1 4
192.168.0.2 7
and I need to obtain this:
IP Value
192.168.0.1 1
192.168.0.1 2
192.168.0.1 4
192.168.0.2 3
192.168.0.2 5
192.168.0.2 7
Is there a way to do this withous using multivalue fields? It's like a sort Value with "by" clause.
Thank you!
sort is the correct answer as mentioned by others but since expected output has IPs as well as Values sorted in it hence it actually should be:
yourBaseSearch | sort by IP, Value
OR without by
yourBaseSearch
| sort IP, Value
Use the sort command? 🙂
... | sort Value
http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Sort
works! thx.
Please accept the answer.
I think you mean
| sort IP