<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk email csv column order not being the same as search in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/639981#M16040</link>
    <description>&lt;P&gt;Be specific here.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2023 18:17:56 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2023-04-14T18:17:56Z</dc:date>
    <item>
      <title>Why is Splunk email csv column order not being the same as search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/639816#M16020</link>
      <description>&lt;P&gt;Recently we discovered that our Splunk sendemail command in combination with the sendcsv option is no longer using the same order for the columns as the search itself. We suspect that that has been broken since we upgraded from 8.x to 9.0.3. We've tried messing around with the width_sort_columns, but this hasn't produced the results we're looking for. Has anyone else experienced the same issues and maybe already found a solution?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 18:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/639816#M16020</guid>
      <dc:creator>Tim_Accenture</dc:creator>
      <dc:date>2023-04-14T18:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk email csv column order not being the same as search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/639981#M16040</link>
      <description>&lt;P&gt;Be specific here.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 18:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/639981#M16040</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-14T18:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk email csv column order not being the same as search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640148#M16070</link>
      <description>&lt;P&gt;When using the | sendemail command and setting 'sendcsv=true' in our old situation the attached .csv file would have the same column order of our search. It appears that since upgrading to 9.0.3 from 8.1.x, we can no longer influence the column order in our .csv file.&lt;/P&gt;&lt;P&gt;An example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our search would be&amp;nbsp;&lt;/P&gt;&lt;P&gt;| ....&lt;BR /&gt;| table a b c&lt;BR /&gt;| sendemail to=... sendcsv=true&lt;BR /&gt;&lt;BR /&gt;Which in our old situation would keep the column order of our | table command. Now it would be 'b c a' in the .csv file attached in the mail instead of 'a b c'. Whatever order for the table we set in our search no longer influences the .csv file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this clarifies it a bit.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 05:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640148#M16070</guid>
      <dc:creator>Tim_Accenture</dc:creator>
      <dc:date>2023-04-17T05:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk email csv column order not being the same as search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640295#M16097</link>
      <description>&lt;P&gt;Could be this:&lt;BR /&gt;&lt;BR /&gt;width_sort_columns&lt;STRONG&gt;Syntax:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;width_sort_columns=&amp;lt;boolean&amp;gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;This is only valid for plain text emails. Specifies whether the columns should be sorted by their width.&lt;STRONG&gt;Default:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;true&lt;BR /&gt;&lt;BR /&gt;From here:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Sendemail" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Sendemail&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 21:20:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640295#M16097</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-17T21:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk email csv column order not being the same as search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640976#M16154</link>
      <description>&lt;P&gt;Thanks for the suggestion. We tried that already and that is not it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example1.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25029iC5AD5C82892274BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="example1.png" alt="example1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;still gives the following since version 9.0.x.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tim_Accenture_0-1682083612182.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25030iE558568A7B0F84EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tim_Accenture_0-1682083612182.png" alt="Tim_Accenture_0-1682083612182.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm starting to think this is just a bug. I have been able to confirm this behavior on 2 separate Splunk environments already since we upgraded them from version 8 to 9.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 13:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640976#M16154</guid>
      <dc:creator>Tim_Accenture</dc:creator>
      <dc:date>2023-04-21T13:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk email csv column order not being the same as search?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640977#M16155</link>
      <description>&lt;P&gt;Open a support ticket but ALSO go to the documentation page that I listed and go to the bottom and send them feedback and point to this answers post.&amp;nbsp; They dox team is GREAT and they will get to the bottom of it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 13:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Splunk-email-csv-column-order-not-being-the-same-as/m-p/640977#M16155</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-21T13:52:18Z</dc:date>
    </item>
  </channel>
</rss>

