All Apps and Add-ons

Sort option in the table for Date Field not working.

Ashwini008
Builder

I have converted the date field to epoch time and results obtained from the query is sorted as expected, but while clicking on the sort option in the table for the Date Field, date between 2021 and 2020 are not sorting in the ascending order. I am using Splunk 7.0 version, is this because of the instance issue? because from my query i am getting correct result only when clicked on sort icon it is not sorted properly.

Ashwini008_0-1610979678754.png

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Ashwini008,

If you can change the date format to "%Y/%m/%d" you will be able to sort on GUI.

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Date field shown is not in epoch form.  It's text and so is sorted lexicographically.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ashwini008
Builder

I have converted the date into epoch form and sorted it, after sorting i have displayed the results in human readable format. only in the table i am facing the issue when i click on the sort option.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...