<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sort by Date &amp; Time in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461819#M6700</link>
    <description>&lt;P&gt;@oscar84x  :Base search | search feedback=Good | search "feedbackmessage"=* | table  date , time , feedback feedbackmessage | sort - Date &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Date                                                   time             feedback    feedbackmessage&lt;/STRONG&gt;&lt;BR /&gt;
Wednesday December 4, 2019    8:24:37 AM        Good          hjsdn&lt;BR /&gt;
Wednesday December 11, 2019  3:33:35 PM        Good          hduasjklk&lt;BR /&gt;
Wednesaday December 4, 2019 12:05:30 PM       Bad             afstgahjd&lt;BR /&gt;
Thursday December 5, 2019        7:53:29 PM         IDEA           qtdygwuhsk&lt;/P&gt;

&lt;P&gt;output shld be date &amp;amp; time order in order like this &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Wednesday December 4, 2019 8:24:37 AM&lt;BR /&gt;
Wednesaday December 4, 2019 12:05:30 PM&lt;BR /&gt;
Thursday December 5, 2019 7:53:29 PM&lt;BR /&gt;
Wednesday December 11, 2019 3:33:35 PM&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Dec 2019 17:08:40 GMT</pubDate>
    <dc:creator>monipinni</dc:creator>
    <dc:date>2019-12-13T17:08:40Z</dc:date>
    <item>
      <title>sort by Date &amp; Time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461817#M6698</link>
      <description>&lt;P&gt;Wednesday December 4, 2019           8:24:37 AM&lt;BR /&gt;
Wednesday December 11, 2019         3:33:35 PM&lt;BR /&gt;
Wednesaday December 4, 2019         12:05:30 PM&lt;BR /&gt;
Thursday December 5, 2019                7:53:29 PM&lt;/P&gt;

&lt;P&gt;How to sort by date &amp;amp; time as per calender? Tried sort - Date , -Time&lt;/P&gt;

&lt;P&gt;I am looking for output like &lt;/P&gt;

&lt;P&gt;Wednesday December 4, 2019           8:24:37 AM&lt;BR /&gt;
Wednesaday December 4, 2019         12:05:30 PM&lt;BR /&gt;
Thursday December 5, 2019                7:53:29 PM&lt;BR /&gt;
Wednesday December 11, 2019         3:33:35 PM&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 16:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461817#M6698</guid>
      <dc:creator>monipinni</dc:creator>
      <dc:date>2019-12-13T16:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: sort by Date &amp; Time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461818#M6699</link>
      <description>&lt;P&gt;Can you share some more information? event samples and your query?&lt;BR /&gt;
We'd need to see what fields you're working with.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 16:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461818#M6699</guid>
      <dc:creator>oscar84x</dc:creator>
      <dc:date>2019-12-13T16:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: sort by Date &amp; Time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461819#M6700</link>
      <description>&lt;P&gt;@oscar84x  :Base search | search feedback=Good | search "feedbackmessage"=* | table  date , time , feedback feedbackmessage | sort - Date &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Date                                                   time             feedback    feedbackmessage&lt;/STRONG&gt;&lt;BR /&gt;
Wednesday December 4, 2019    8:24:37 AM        Good          hjsdn&lt;BR /&gt;
Wednesday December 11, 2019  3:33:35 PM        Good          hduasjklk&lt;BR /&gt;
Wednesaday December 4, 2019 12:05:30 PM       Bad             afstgahjd&lt;BR /&gt;
Thursday December 5, 2019        7:53:29 PM         IDEA           qtdygwuhsk&lt;/P&gt;

&lt;P&gt;output shld be date &amp;amp; time order in order like this &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Wednesday December 4, 2019 8:24:37 AM&lt;BR /&gt;
Wednesaday December 4, 2019 12:05:30 PM&lt;BR /&gt;
Thursday December 5, 2019 7:53:29 PM&lt;BR /&gt;
Wednesday December 11, 2019 3:33:35 PM&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 17:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461819#M6700</guid>
      <dc:creator>monipinni</dc:creator>
      <dc:date>2019-12-13T17:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: sort by Date &amp; Time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461820#M6701</link>
      <description>&lt;P&gt;You can create a date sort field, use it for sorting, and then throw it away:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval date="Wednesday December 4, 2019"
| eval time="8:24:37 AM"
| eval feedback="Good"
| eval feedbackmessage="hsjdn"
| eval dateTime=date." ".time | rex field=dateTime mode=sed "s/\w+\s(.*)/\1/g"
| eval dateSort=strptime(dateTime,"%b %d, %Y %I:%M:%S %p")
| sort dateSort
| fields - dateSort
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 13 Dec 2019 18:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461820#M6701</guid>
      <dc:creator>jpolvino</dc:creator>
      <dc:date>2019-12-13T18:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: sort by Date &amp; Time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461821#M6702</link>
      <description>&lt;P&gt;Date strings are sorted in ASCII order, not date order.  The solution is to parse the dates into a separate field for sorting.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Base search | search feedback=Good | search "feedbackmessage"=* 
| eval epoch=sprptime(Date, "%A %B %d, %Y %I:%M:%S %p") | sort + epoch | table Date, time, feedback, feebackmessage
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 13 Dec 2019 18:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/sort-by-Date-Time/m-p/461821#M6702</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-12-13T18:03:55Z</dc:date>
    </item>
  </channel>
</rss>

