<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sort by time in a chart with time header names in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452464#M128129</link>
    <description>&lt;P&gt;I solved it by appending a "-01" on monthYear and then transposing the chart. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal
| timechart span=1h count 
| eval hour = strftime(_time, "%H:%M") 
| eval monthYear = strftime(_time, "%b-%y") 
| chart limit=0 sum(count) as inflow over monthYear by hour 
| eval dateSort = monthYear . "-1" 
| eval dateSortEpoch = strptime(dateSort, "%b-%y-%d") 
| sort dateSortEpoch 
| transpose 0 column_name="Time" header_field="monthYear" 
| search NOT Time = "date*"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 10 May 2019 09:30:19 GMT</pubDate>
    <dc:creator>dojiepreji</dc:creator>
    <dc:date>2019-05-10T09:30:19Z</dc:date>
    <item>
      <title>Sort by time in a chart with time header names</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452462#M128127</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a search table that aims to show the inflow of tickets for a time range.&lt;/P&gt;

&lt;P&gt;Here is what it looks like...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Hour     |     Apr-18     |     Apr-19     |     Aug-18     |     Dec-18
0:00              2                 3               5                3 
1:00              2                13               2                1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is the search for this table...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal
| bin _time span=1h 
| eval hour = strftime(_time, "%H:%M") 
| eval monthYear = strftime(_time, "%b-%y") 
| stats count(ticketNumber) as inflow values(hour) as hour values(monthYear) as monthYear by _time 
| chart limit=0 sum(inflow) as inflow over hour by monthYear
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I want to sort  my columns by date, (Apr-18, Aug-18, Dec-18, Apr-19). I cannot use "fields ..." because the user is free to input the time range that the table will display. &lt;/P&gt;

&lt;P&gt;Any help would be appreciated. Thank you. &lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 08:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452462#M128127</guid>
      <dc:creator>dojiepreji</dc:creator>
      <dc:date>2019-05-10T08:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sort by time in a chart with time header names</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452463#M128128</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Check this link&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/294224/how-to-sort-column-chart-based-on-month-year-order.html"&gt;https://answers.splunk.com/answers/294224/how-to-sort-column-chart-based-on-month-year-order.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 08:56:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452463#M128128</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-05-10T08:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Sort by time in a chart with time header names</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452464#M128129</link>
      <description>&lt;P&gt;I solved it by appending a "-01" on monthYear and then transposing the chart. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal
| timechart span=1h count 
| eval hour = strftime(_time, "%H:%M") 
| eval monthYear = strftime(_time, "%b-%y") 
| chart limit=0 sum(count) as inflow over monthYear by hour 
| eval dateSort = monthYear . "-1" 
| eval dateSortEpoch = strptime(dateSort, "%b-%y-%d") 
| sort dateSortEpoch 
| transpose 0 column_name="Time" header_field="monthYear" 
| search NOT Time = "date*"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 May 2019 09:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-by-time-in-a-chart-with-time-header-names/m-p/452464#M128129</guid>
      <dc:creator>dojiepreji</dc:creator>
      <dc:date>2019-05-10T09:30:19Z</dc:date>
    </item>
  </channel>
</rss>

