<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are events not sorting in Chronological Order with a basic search? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437764#M124642</link>
    <description>&lt;P&gt;It's certainly a little strange.      In general if you have  &lt;CODE&gt;searchterms | &amp;lt;some transforming command&amp;gt;&lt;/CODE&gt;   the order of the events going into the transforming command are not actually guaranteed to be in time order.     (Yes it used to be true long long ago, but with distsearch and search-in-separate-process and various parallel bucket things they did,  it's no longer always true) &lt;/P&gt;

&lt;P&gt;HOWEVER why am I talking about transforming commands?  You're seeing this happen in a simple events search.   Yes, I am surprised.&lt;BR /&gt;&lt;BR /&gt;
I suspect that it's something you don't normally see unless the timestamps on the events are a little different from the actual wall-clock-time when they come into the system?   Is there anything else notable about those events whose timestamps are off from the others? &lt;/P&gt;</description>
    <pubDate>Sat, 01 Sep 2018 00:27:08 GMT</pubDate>
    <dc:creator>sideview</dc:creator>
    <dc:date>2018-09-01T00:27:08Z</dc:date>
    <item>
      <title>Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437762#M124640</link>
      <description>&lt;P&gt;Today, I noticed that, when performing a basic search, the events are not sorted chronologically. Additionally, not all events 'match up' correctly to the timeline.&lt;/P&gt;

&lt;P&gt;I have not found any other posts which document this strange behavior.&lt;/P&gt;

&lt;P&gt;With a simple &lt;CODE&gt;| sort _time&lt;/CODE&gt;, the events sort as expected and correlate to the timeline accurately.&lt;/P&gt;

&lt;P&gt;The deployment was upgraded from 7.0.2 to 7.1.2 one week ago.&lt;/P&gt;

&lt;P&gt;Here's some screenshots that show the behavior:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Events not in Chronological Order"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5693i1B8B50D932E6D4C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Events not in Chronological Order" alt="Events not in Chronological Order" /&gt;&lt;/span&gt;&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="Events not Correlated with Timeline"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5694iF763AFB7D984B097/image-size/large?v=v2&amp;amp;px=999" role="button" title="Events not Correlated with Timeline" alt="Events not Correlated with Timeline" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Does anyone have any ideas how to fix this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 22:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437762#M124640</guid>
      <dc:creator>rtev</dc:creator>
      <dc:date>2018-08-31T22:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437763#M124641</link>
      <description>&lt;P&gt;I can't edit my own post... Correction: The version was upgraded to 7.1.2.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 00:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437763#M124641</guid>
      <dc:creator>rtev</dc:creator>
      <dc:date>2018-09-01T00:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437764#M124642</link>
      <description>&lt;P&gt;It's certainly a little strange.      In general if you have  &lt;CODE&gt;searchterms | &amp;lt;some transforming command&amp;gt;&lt;/CODE&gt;   the order of the events going into the transforming command are not actually guaranteed to be in time order.     (Yes it used to be true long long ago, but with distsearch and search-in-separate-process and various parallel bucket things they did,  it's no longer always true) &lt;/P&gt;

&lt;P&gt;HOWEVER why am I talking about transforming commands?  You're seeing this happen in a simple events search.   Yes, I am surprised.&lt;BR /&gt;&lt;BR /&gt;
I suspect that it's something you don't normally see unless the timestamps on the events are a little different from the actual wall-clock-time when they come into the system?   Is there anything else notable about those events whose timestamps are off from the others? &lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 00:27:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437764#M124642</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2018-09-01T00:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437765#M124643</link>
      <description>&lt;P&gt;The timestamps are coming in as Unix Epoch time and are extracted correctly. I've checked the difference between the _indextime and _time and there are no events for which the skew is greater than 4-5 seconds. I'd be glad to share a couple of examples of the data that is being ingested and the related props configuration if you think that might shed some light on the matter. Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 00:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437765#M124643</guid>
      <dc:creator>rtev</dc:creator>
      <dc:date>2018-09-01T00:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437766#M124644</link>
      <description>&lt;P&gt;I should mention that the timestamps resolve down to milliseconds...&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 00:57:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437766#M124644</guid>
      <dc:creator>rtev</dc:creator>
      <dc:date>2018-09-01T00:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437767#M124645</link>
      <description>&lt;P&gt;I should also mention that Transparent Huge Page memory management was disabled one day ago on all (Linux) hosts across the cluster.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 01:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437767#M124645</guid>
      <dc:creator>rtev</dc:creator>
      <dc:date>2018-09-01T01:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437768#M124646</link>
      <description>&lt;P&gt;Yeah, we noticed the same thing on our side. Opened a ticket with Splunk and they confirmed that it was a known bug:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;This behavior has been reported as a bug on a Jira (SPL-154973) document, and has been fixed on version 7.1.3.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;And the official workaround is to explicitly sort the events.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 13:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437768#M124646</guid>
      <dc:creator>Ranazar</dc:creator>
      <dc:date>2018-09-01T13:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437769#M124647</link>
      <description>&lt;P&gt;Incidentally (and I'm not sure if this is a symptom of the same issue), I've actually had the search results show the same events multiple times (as though they were different events). As before, explicit sorting fixes this.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 14:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437769#M124647</guid>
      <dc:creator>Ranazar</dc:creator>
      <dc:date>2018-09-01T14:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events not sorting in Chronological Order with a basic search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437770#M124648</link>
      <description>&lt;P&gt;Earlier this morning I noticed some other similar aberrant behaviors related to events showing up multiple times when zooming into different slices of the timeline. Similarly I don't know if it's a symptom of the same issue but it seems likely. I will accept your answer when things get straightened out. Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 15:07:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-events-not-sorting-in-Chronological-Order-with-a-basic/m-p/437770#M124648</guid>
      <dc:creator>rtev</dc:creator>
      <dc:date>2018-09-01T15:07:47Z</dc:date>
    </item>
  </channel>
</rss>

