<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to sort on multiple values in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704172#M57697</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt;&amp;nbsp; tried but not working&lt;/P&gt;</description>
    <pubDate>Tue, 12 Nov 2024 14:32:43 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2024-11-12T14:32:43Z</dc:date>
    <item>
      <title>How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704164#M57695</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have below panel query&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I want to sort on the basis of busdate and start time, But results are not coming correct.Could anyone guide on this&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Currently its sorting on bus date but no&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33448i5E0F5505E834E8B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;t start time. Please guide&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log""StatisticBalancer - statisticData: StatisticData" "CARS.UNB."|rex "totalOutputRecords=(?&amp;amp;lt;totalOutputRecords&amp;amp;gt;),busDt=(?&amp;amp;lt;busDt&amp;amp;gt;),fileName=(?&amp;amp;lt;fileName&amp;amp;gt;),totalAchCurrOutstBalAmt=(?&amp;amp;lt;totalAchCurrOutstBalAmt&amp;amp;gt;),totalAchBalLastStmtAmt=(?&amp;amp;lt;totalAchBalLastStmtAmt&amp;amp;gt;),totalClosingBal=(?&amp;amp;lt;totalClosingBal&amp;amp;gt;),totalRecordsWritten=(?&amp;amp;lt;totalRecordsWritten&amp;amp;gt;),totalRecords=(?&amp;amp;lt;totalRecords&amp;amp;gt;)"|eval totalAchCurrOutstBalAmt=tonumber(mvindex(split(totalAchCurrOutstBalAmt,"E"),0)) * pow(10,tonumber(mvindex(split(totalAchCurrOutstBalAmt,"E"),1)))|eval totalAchBalLastStmtAmt=tonumber(mvindex(split(totalAchBalLastStmtAmt,"E"),0)) * pow(10,tonumber(mvindex(split(totalAchBalLastStmtAmt,"E"),1)))|eval totalClosingBal=tonumber(mvindex(split(totalClosingBal,"E"),0)) * pow(10,tonumber(mvindex(split(totalClosingBal,"E"),1)))|table busDt fileName totalAchCurrOutstBalAmt totalAchBalLastStmtAmt totalClosingBal totalRecordsWritten totalRecords|sort busDt|appendcols[search index="abc"sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" | rex "CARS\.UNB(CTR)?\.(?&amp;amp;lt;CARS_ID&amp;amp;gt;\w+)"&lt;BR /&gt;| transaction CARS_ID startswith="Reading Control-File /absin/CARS.UNBCTR." endswith="Completed Settlement file processing, CARS.UNB."&lt;BR /&gt;|eval StartTime=min(_time)|eval EndTime=StartTime+duration|eval duration_min=floor(duration/60) |rename duration_min as CARS.UNB_Duration| table StartTime EndTime CARS.UNB_Duration]| fieldformat StartTime = strftime(StartTime, "%F %T.%3N")| fieldformat EndTime = strftime(EndTime, "%F %T.%3N")|appendcols[search index="600000304_d_gridgain_idx*" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "FileEventCreator - Completed Settlement file processing" "CARS.UNB."|rex "FileEventCreator - Completed Settlement file processing, (?&amp;amp;lt;file&amp;amp;gt;[^ ]*) records processed: (?&amp;amp;lt;records_processed&amp;amp;gt;\d+)"| rename file as Files|rename records_processed as Records| table Files Records]|appendcols[search index="600000304_d_gridgain_idx*" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"| head 7&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully"&lt;BR /&gt;| table EBNCStatus True]|rename busDt as Business_Date|rename fileName as File_Name|rename CARS.UNB_Duration as CARS.UNB_Duration(Minutes)|table Business_Date File_Name StartTime EndTime CARS.UNB_Duration(Minutes) Records totalClosingBal totalRecordsWritten totalRecords EBNCStatus&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 13:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704164#M57695</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-12T13:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704166#M57696</link>
      <description>&lt;P&gt;You only have a sort on Business Date but you never say to sort on Start Time as well.&amp;nbsp; In fact the field Start Time is evaluated after the sort is done.&amp;nbsp; If you want a sort it should be done after both fields are available in a sortable format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| sort "Business_Date" "StartTime"&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 13:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704166#M57696</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-12T13:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704172#M57697</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt;&amp;nbsp; tried but not working&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 14:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704172#M57697</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-12T14:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704179#M57699</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt;&amp;nbsp; any option&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 15:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704179#M57699</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-12T15:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704192#M57701</link>
      <description>&lt;P&gt;1. Just saying "not working" doesn't say anything. We have no idea what the results should look like, what they actually look like, what data you have and so on.&lt;/P&gt;&lt;P&gt;2. Apart from your main question I see another issue woth your search - you sort first, then add some data with appendcols. Are you absolutely sure that you get right data in right places?&lt;/P&gt;&lt;P&gt;3. And finally, if you post SPL code please do so as either code block (the &amp;lt;/&amp;gt; symbol at the top of the text-edit widget) or as a preformatted style so that it doesn't get butchered into this unreadable blob of text.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 16:13:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704192#M57701</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-12T16:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704195#M57702</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I am putting this&lt;/P&gt;&lt;P&gt;sort "Business_Date" "StartTime"&lt;/P&gt;&lt;P&gt;Its only sorting on Business_Date and not startTime&lt;/P&gt;&lt;P&gt;Could you please suggest&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 16:42:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704195#M57702</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-12T16:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704202#M57703</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| sort 0 'Business_Date' 'StartTime'&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 12 Nov 2024 17:57:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704202#M57703</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-12T17:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704205#M57704</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried the below query&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;|sort 0 'Business_Date' 'StartTime'&lt;/LI-CODE&gt;
&lt;P&gt;Its sorting only on StartTime not on business date&lt;/P&gt;
&lt;P&gt;Could you please suggest&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 19:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704205#M57704</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-12T19:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704224#M57707</link>
      <description>&lt;P&gt;Please can you show an example of where the events are not sorted by these two fields?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 23:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704224#M57707</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-12T23:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704239#M57710</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;please find my below query&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log""StatisticBalancer - statisticData: StatisticData" "CARS.UNB."|rex "totalOutputRecords=(?&amp;amp;lt;totalOutputRecords&amp;amp;gt;),busDt=(?&amp;amp;lt;busDt&amp;amp;gt;),fileName=(?&amp;amp;lt;fileName&amp;amp;gt;),totalAchCurrOutstBalAmt=(?&amp;amp;lt;totalAchCurrOutstBalAmt&amp;amp;gt;),totalAchBalLastStmtAmt=(?&amp;amp;lt;totalAchBalLastStmtAmt&amp;amp;gt;),totalClosingBal=(?&amp;amp;lt;totalClosingBal&amp;amp;gt;),totalRecordsWritten=(?&amp;amp;lt;totalRecordsWritten&amp;amp;gt;),totalRecords=(?&amp;amp;lt;totalRecords&amp;amp;gt;)"|eval totalAchCurrOutstBalAmt=tonumber(mvindex(split(totalAchCurrOutstBalAmt,"E"),0)) * pow(10,tonumber(mvindex(split(totalAchCurrOutstBalAmt,"E"),1)))|eval totalAchBalLastStmtAmt=tonumber(mvindex(split(totalAchBalLastStmtAmt,"E"),0)) * pow(10,tonumber(mvindex(split(totalAchBalLastStmtAmt,"E"),1)))|eval totalClosingBal=tonumber(mvindex(split(totalClosingBal,"E"),0)) * pow(10,tonumber(mvindex(split(totalClosingBal,"E"),1)))|table busDt fileName totalAchCurrOutstBalAmt totalAchBalLastStmtAmt totalClosingBal totalRecordsWritten totalRecords|appendcols[search index="600000304_d_gridgain_idx*"sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" | rex "CARS\.UNB(CTR)?\.(?&amp;amp;lt;CARS_ID&amp;amp;gt;\w+)"&lt;BR /&gt;| transaction CARS_ID startswith="Reading Control-File /absin/CARS.UNBCTR." endswith="Completed Settlement file processing, CARS.UNB."&lt;BR /&gt;|eval StartTime=min(_time)|eval EndTime=StartTime+duration|eval duration_min=floor(duration/60) |rename duration_min as CARS.UNB_Duration| table StartTime EndTime CARS.UNB_Duration]| fieldformat StartTime = strftime(StartTime, "%F %T.%3N")| fieldformat EndTime = strftime(EndTime, "%F %T.%3N")|appendcols[search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "FileEventCreator - Completed Settlement file processing" "CARS.UNB."|rex "FileEventCreator - Completed Settlement file processing, (?&amp;amp;lt;file&amp;amp;gt;[^ ]*) records processed: (?&amp;amp;lt;records_processed&amp;amp;gt;\d+)"| rename file as Files|rename records_processed as Records| table Files Records]|appendcols[search index="600000304_d_gridgain_idx*" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully" | head 7&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully"&lt;BR /&gt;| table EBNCStatus True]|rename busDt as Business_Date|rename fileName as File_Name|rename CARS.UNB_Duration as CARS.UNB_Duration(Minutes)|table Business_Date File_Name StartTime EndTime CARS.UNB_Duration(Minutes) Records totalClosingBal totalRecordsWritten totalRecords EBNCStatus | sort 0 'Business_Date' 'StartTime'&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 03:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704239#M57710</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-13T03:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704252#M57712</link>
      <description>&lt;P&gt;Please show the results not the search&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 08:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704252#M57712</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-13T08:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort on multiple values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704263#M57714</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can see in result StartTime is sorted but businedd date is coming as 11/07/2024 in front of that . It is not sorted&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Result.PNG" style="width: 936px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33457i64A0B0E59DED7D2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Result.PNG" alt="Result.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 10:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-sort-on-multiple-values/m-p/704263#M57714</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2024-11-13T10:42:22Z</dc:date>
    </item>
  </channel>
</rss>

