<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sort fieldnames in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508639#M142109</link>
    <description>&lt;P&gt;AccountName FAILURE SUCCESS IMPACT LOSS% Total&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Account1&lt;/TD&gt;&lt;TD&gt;2000&lt;/TD&gt;&lt;TD&gt;149&lt;/TD&gt;&lt;TD&gt;0.1&lt;/TD&gt;&lt;TD&gt;11.33&lt;/TD&gt;&lt;TD&gt;10804&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Account2&lt;/TD&gt;&lt;TD&gt;2081&lt;/TD&gt;&lt;TD&gt;262&lt;/TD&gt;&lt;TD&gt;0.10&lt;/TD&gt;&lt;TD&gt;9.55&lt;/TD&gt;&lt;TD&gt;2043&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Account3&lt;/TD&gt;&lt;TD&gt;1630&lt;/TD&gt;&lt;TD&gt;1554&lt;/TD&gt;&lt;TD&gt;0.01&lt;/TD&gt;&lt;TD&gt;9.49&lt;/TD&gt;&lt;TD&gt;1017&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output was from inner join&lt;/P&gt;&lt;P&gt;I want the output like - alignment of field names. Sorting the order of field names.&lt;/P&gt;&lt;P&gt;Before -&amp;nbsp;&lt;/P&gt;&lt;P&gt;AccountName&amp;nbsp; &amp;nbsp; FAILURE SUCCESS&amp;nbsp; IMPACT LOSS% Total&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After sorting&amp;nbsp; should be -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AccountName&amp;nbsp; &amp;nbsp; FAILURE SUCCESS Total&amp;nbsp; &amp;nbsp;IMPACT LOSS%&lt;/P&gt;</description>
    <pubDate>Sun, 12 Jul 2020 00:28:30 GMT</pubDate>
    <dc:creator>skodak</dc:creator>
    <dc:date>2020-07-12T00:28:30Z</dc:date>
    <item>
      <title>Sort fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508639#M142109</link>
      <description>&lt;P&gt;AccountName FAILURE SUCCESS IMPACT LOSS% Total&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Account1&lt;/TD&gt;&lt;TD&gt;2000&lt;/TD&gt;&lt;TD&gt;149&lt;/TD&gt;&lt;TD&gt;0.1&lt;/TD&gt;&lt;TD&gt;11.33&lt;/TD&gt;&lt;TD&gt;10804&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Account2&lt;/TD&gt;&lt;TD&gt;2081&lt;/TD&gt;&lt;TD&gt;262&lt;/TD&gt;&lt;TD&gt;0.10&lt;/TD&gt;&lt;TD&gt;9.55&lt;/TD&gt;&lt;TD&gt;2043&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Account3&lt;/TD&gt;&lt;TD&gt;1630&lt;/TD&gt;&lt;TD&gt;1554&lt;/TD&gt;&lt;TD&gt;0.01&lt;/TD&gt;&lt;TD&gt;9.49&lt;/TD&gt;&lt;TD&gt;1017&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output was from inner join&lt;/P&gt;&lt;P&gt;I want the output like - alignment of field names. Sorting the order of field names.&lt;/P&gt;&lt;P&gt;Before -&amp;nbsp;&lt;/P&gt;&lt;P&gt;AccountName&amp;nbsp; &amp;nbsp; FAILURE SUCCESS&amp;nbsp; IMPACT LOSS% Total&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After sorting&amp;nbsp; should be -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AccountName&amp;nbsp; &amp;nbsp; FAILURE SUCCESS Total&amp;nbsp; &amp;nbsp;IMPACT LOSS%&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 00:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508639#M142109</guid>
      <dc:creator>skodak</dc:creator>
      <dc:date>2020-07-12T00:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sort fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508640#M142110</link>
      <description>&lt;P&gt;Use the &lt;FONT face="courier new,courier"&gt;table&lt;/FONT&gt; command to specify the order in which fields should be displayed.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 00:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508640#M142110</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-12T00:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sort fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508643#M142112</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;I have used table in second query and chart in first. I am not getting the desired result.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 02:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508643#M142112</guid>
      <dc:creator>skodak</dc:creator>
      <dc:date>2020-07-12T02:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sort fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508673#M142119</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal 
| head 3 
| fields _raw _time 
| streamstats count 
| eval _raw=case(count=1,"AccountName=Account1,FAILURE=2000,SUCCESS=149,IMPACT=0.1,LOSS%=11.33,Total=10804",count=2,"AccountName=Account2,FAILURE=2081,SUCCESS=262,IMPACT=0.10,LOSS%=9.55,Total=2043"
    ,count=3,"AccountName=Account3,FAILURE=1630,SUCCESS=1554,IMPACT=0.01,LOSS%=9.49,Total=1017") 
| fields - count 
| kv 
| rename LOSS as "LOSS%" 
| table AccountName FAILURE SUCCESS Total IMPACT LOSS%&lt;/LI-CODE&gt;&lt;P&gt;I'm not sure when it can't&amp;nbsp;&lt;STRONG&gt;table&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 09:18:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508673#M142119</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-12T09:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sort fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508687#M142122</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp; I have mutliple Account_NM which will be generated in realtime. The ACCOUNT_NM which I provided was sample data.&lt;/P&gt;&lt;P&gt;Thank you for the info though &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 13:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508687#M142122</guid>
      <dc:creator>skodak</dc:creator>
      <dc:date>2020-07-12T13:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sort fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508696#M142127</link>
      <description>The table command is the one to use to re-order fields for display.&lt;BR /&gt;Please share your query so we can see what may be throwing things off.</description>
      <pubDate>Sun, 12 Jul 2020 17:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sort-fieldnames/m-p/508696#M142127</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-12T17:13:04Z</dc:date>
    </item>
  </channel>
</rss>

