<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: custom sort field values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569155#M198370</link>
    <description>&lt;P&gt;these are port numbers and i want sort port with same numbers,&lt;/P&gt;&lt;P&gt;like this,&lt;/P&gt;&lt;P&gt;0/1/0/0&lt;/P&gt;&lt;P&gt;0/1/0/0&lt;/P&gt;&lt;P&gt;0/2/1/1&lt;/P&gt;&lt;P&gt;0/2/2/1&lt;/P&gt;&lt;P&gt;0/2/2/1&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 14:08:00 GMT</pubDate>
    <dc:creator>corehan</dc:creator>
    <dc:date>2021-09-30T14:08:00Z</dc:date>
    <item>
      <title>custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569138#M198359</link>
      <description>&lt;P&gt;Hello dears,&lt;/P&gt;&lt;P&gt;How can i sort these field values ?&lt;/P&gt;&lt;P&gt;Field = "port"&lt;/P&gt;&lt;DIV class="multivalue-subcell"&gt;0/1/0/2/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/8/0/7/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/2/0/3/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/5/0/2/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/6/0/3/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/16/0/2&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/18/0/6&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/16/0/5&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/4/0/2/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/6/0/2/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/18/0/2&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;0/12/0/4&lt;/DIV&gt;&lt;DIV class="multivalue-subcell highlighted"&gt;0/3/0/7/&lt;/DIV&gt;&lt;DIV class="multivalue-subcell highlighted"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="multivalue-subcell highlighted"&gt;Regards.&lt;/DIV&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569138#M198359</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T13:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569143#M198363</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;sort&lt;/FONT&gt; command will sort them for you.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| sort port&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:10:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569143#M198363</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-30T13:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569144#M198364</link>
      <description>&lt;P&gt;this view also sort port but it is not sorting .&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569144#M198364</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T13:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569149#M198367</link>
      <description>&lt;P&gt;Please use more words.&amp;nbsp; What exactly are you trying to do?&amp;nbsp; How exactly are you trying to do it?&amp;nbsp; What are the results?&amp;nbsp; What results did you expect?&amp;nbsp; What problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569149#M198367</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-30T13:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569155#M198370</link>
      <description>&lt;P&gt;these are port numbers and i want sort port with same numbers,&lt;/P&gt;&lt;P&gt;like this,&lt;/P&gt;&lt;P&gt;0/1/0/0&lt;/P&gt;&lt;P&gt;0/1/0/0&lt;/P&gt;&lt;P&gt;0/2/1/1&lt;/P&gt;&lt;P&gt;0/2/2/1&lt;/P&gt;&lt;P&gt;0/2/2/1&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 14:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569155#M198370</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T14:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569162#M198374</link>
      <description>&lt;P&gt;I suppose your problem is that "normal" sort sorts the values as strings (lexicographically) and you want to have them sorted with numerical values of each "field".&lt;/P&gt;&lt;P&gt;Assuming you have your data in a field called "a"&lt;/P&gt;&lt;PRE&gt;&amp;lt;your_search&amp;gt; | rex field=a "(?&amp;lt;d1&amp;gt;\d+)/(?&amp;lt;d2&amp;gt;\d+)/(?&amp;lt;d3&amp;gt;\d+)/(?&amp;lt;d4&amp;gt;\d+)" &lt;BR /&gt;| sort d1 d2 d3 d4 &lt;BR /&gt;| eval a=d1."/".d2."/".d3."/".d4&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 Sep 2021 14:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569162#M198374</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T14:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569169#M198377</link>
      <description>&lt;P&gt;Sorry, i couldn't. Here is the real search query and result. I want the group or sort OLT_Port values;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;base search&amp;gt;&lt;/STRONG&gt; |rex field=ONT "^(?P&amp;lt;ONT&amp;gt;........)" | stats count as Toplam_Sikayet list(Saat) as Saat list(ONT) as OLT_Port list(H) as Hizmet_ID list(REQUESTNAME) as Sikayet by Date,OLT |sort -OLT_Port&lt;BR /&gt;| where Toplam_Sikayet &amp;gt;= 10&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_0-1633014458293.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16228i8B60C6FD0F2C7B98/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_0-1633014458293.png" alt="corehan_0-1633014458293.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569169#M198377</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T15:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569174#M198381</link>
      <description>&lt;P&gt;Ahhh. Again (someone lately had similar problem - wasn't that you?) you're creating one multivalued field. You won't sort your data that way. Even if you managed to sort the data within this one column, there's no way to tell the other multivalued fields to reorder. So that's definitely not something you want.&lt;/P&gt;&lt;P&gt;Do not aggregate the fields.&lt;/P&gt;&lt;P&gt;Just do your stats, sort the data, then aggregate and stats again.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569174#M198381</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T15:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569180#M198383</link>
      <description>&lt;P class="p2"&gt;Give this a try (using mvsort as the field values are multivalued. Also, moving 'where' filter just after stats, filter should be done as early as possible)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base search&amp;gt; |rex field=ONT "^(?P&amp;lt;ONT&amp;gt;........)" | stats count as Toplam_Sikayet list(Saat) as Saat list(ONT) as OLT_Port list(H) as Hizmet_ID list(REQUESTNAME) as Sikayet by Date,OLT 
| where Toplam_Sikayet &amp;gt;= 10 | eval OLT_Port=mvsort(OLT_Port)&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:37:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569180#M198383</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-09-30T15:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569184#M198385</link>
      <description>&lt;P&gt;King Regards, it's ok now.&lt;/P&gt;&lt;P&gt;Also thank you for all other replays.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I love this community. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 16:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569184#M198385</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T16:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569188#M198386</link>
      <description>&lt;P&gt;You're aware that after sorting the order of the port field does not correspond to the order of other mv-fields?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 16:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569188#M198386</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T16:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569194#M198389</link>
      <description>&lt;P&gt;Hmm, you are right. Thank you for attention. Just only OLT_Port field values sorting without other mvalues fields. This is problem.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 17:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569194#M198389</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T17:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569197#M198390</link>
      <description>&lt;P&gt;As I wrote before - mvsort sorts only values in a single multivalued field. Other fields have no way of "knowing" how to reorder.&lt;/P&gt;&lt;P&gt;So you need to sort the data when it's still in separate events and only afterwards aggregate them if needed (do you need those multivalued fields at all? As you can see they have ,any drawbacks)&lt;/P&gt;&lt;P&gt;Anyway, you needed something more like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base search&amp;gt; |rex field=ONT "^(?P&amp;lt;ONT&amp;gt;........)" | stats count as Toplam_Sikayet by Saat ONT H REQUESTNAME Date OLT 
| where Toplam_Sikayet &amp;gt;= 10 | sort ONT | stats sum(Toplam_Sikayet) list(Saat) list(ONT) list(H) list(REQUESTNAME) by Date OLT&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 30 Sep 2021 17:48:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569197#M198390</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T17:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569201#M198391</link>
      <description>&lt;P&gt;OK. It seems I probably overcomplicated things.&lt;/P&gt;&lt;P&gt;You're probably good to go with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base search&amp;gt; |rex field=ONT "^(?P&amp;lt;ONT&amp;gt;........)" | sort ONT | stats count as Toplam_Sikayet list(Saat) as Saat list(ONT) as OLT_Port list(H) as Hizmet_ID list(REQUESTNAME) as Sikayet by Date,OLT 
| where Toplam_Sikayet &amp;gt;= 10 &lt;/LI-CODE&gt;&lt;P&gt;You might want to replace the sorting part with my other solution if it's not sorting numericaly.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 18:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569201#M198391</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T18:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569202#M198392</link>
      <description>&lt;P&gt;If you want the other fields to be sorted according to field OLT_Port, try this version:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base search&amp;gt; |rex field=ONT "^(?P&amp;lt;ONT&amp;gt;........)" 
| stats count by Date OLT Saat ONT H REQUESTNAME
| sort Date OLT ONT
| stats sum(count) as Toplam_Sikayet list(Saat) as Saat list(ONT) as OLT_Port list(H) as Hizmet_ID list(REQUESTNAME) as Sikayet by Date,OLT 
| where Toplam_Sikayet &amp;gt;= 10&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 18:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569202#M198392</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-09-30T18:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569210#M198397</link>
      <description>&lt;P&gt;Hello&amp;nbsp; , It is working which i want but latest solution is more effortless and same result. just only adding&amp;nbsp;&lt;EM&gt;| sort ONT. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;So i will accept this.&lt;/P&gt;&lt;P&gt;Thank you very much, you are very kind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 18:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569210#M198397</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T18:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: custom sort field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569211#M198398</link>
      <description>&lt;P&gt;King regards , thank you again.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 18:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/custom-sort-field-values/m-p/569211#M198398</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-09-30T18:56:07Z</dc:date>
    </item>
  </channel>
</rss>

