<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multivalue field not ordered properly in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/multivalue-field-not-ordered-properly/m-p/625200#M217334</link>
    <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;values&lt;/FONT&gt; function returns values in lexicographical order with no attempts made to retain any associations to other fields.&amp;nbsp; The &lt;FONT face="courier new,courier"&gt;mvsort&lt;/FONT&gt; function won't help because it sorts the values the exact same way.&lt;/P&gt;</description>
    <pubDate>Sat, 24 Dec 2022 00:06:17 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-12-24T00:06:17Z</dc:date>
    <item>
      <title>multivalue field not ordered properly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multivalue-field-not-ordered-properly/m-p/625188#M217331</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i'm trying to calculate the average events weekly by their severity and comparing the daily amount with the weekly average, i created a multivalue field but the values in the field get reordered and they don't match the rest of the data (the severity multivalue field),&amp;nbsp; I tried using mvsort() but it did not work, what did i do wrong? Thank you for any help. Query, results and expected results below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=myindex earliest=-7d@d latest=now()&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | bin _time span=1d&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | fields _time, severity&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | stats count by _time, severity&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eventstats avg(count) as average by severity&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval change_percent=round(((count-average)*100)/count,0)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval average=round(average,2)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval change_percent=change_percent+"%"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | table _time severity count average change_percent&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | stats values(severity) as severity, values(count) as AlertCount, values(average) as average, values(change_percent) as change_percent by _time&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | sort - _time&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval average=mvsort(average)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval change_percent=mvsort(change_percent)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval AlertCount=mvsort(AlertCount)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; | eval severity=mvsort(severity)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="98px" height="25px"&gt;_time&lt;/TD&gt;&lt;TD width="107.375px" height="25px"&gt;&lt;DIV class=""&gt;severity&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="90px" height="25px"&gt;&lt;DIV class=""&gt;AlertCount&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.8021px" height="25px"&gt;&lt;DIV class=""&gt;average&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="129.49px" height="25px"&gt;&lt;DIV class=""&gt;change_percent&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98px" height="47px"&gt;2022-12-23&lt;/TD&gt;&lt;TD width="107.375px" height="47px"&gt;&lt;DIV class=""&gt;High&lt;/DIV&gt;&lt;DIV class=""&gt;Informational&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="90px" height="47px"&gt;&lt;DIV class=""&gt;3&lt;/DIV&gt;&lt;DIV class=""&gt;8&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.8021px" height="47px"&gt;&lt;DIV class=""&gt;3.25&lt;/DIV&gt;&lt;DIV class=""&gt;3.67&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="129.49px" height="47px"&gt;&lt;DIV class=""&gt;-22%&lt;/DIV&gt;&lt;DIV class=""&gt;59%&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98px" height="47px"&gt;2022-12-22&lt;/TD&gt;&lt;TD width="107.375px" height="47px"&gt;High&lt;/TD&gt;&lt;TD width="90px" height="47px"&gt;1&lt;/TD&gt;&lt;TD width="67.8021px" height="47px"&gt;3.25&lt;/TD&gt;&lt;TD width="129.49px" height="47px"&gt;-225%&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98px" height="47px"&gt;2022-12-21&lt;/TD&gt;&lt;TD width="107.375px" height="47px"&gt;&lt;DIV class=""&gt;High&lt;/DIV&gt;&lt;DIV class=""&gt;Informational&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="90px" height="47px"&gt;3&lt;/TD&gt;&lt;TD width="67.8021px" height="47px"&gt;&lt;DIV class=""&gt;3.25&lt;/DIV&gt;&lt;DIV class=""&gt;3.67&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="129.49px" height="47px"&gt;&lt;DIV class=""&gt;-22%&lt;/DIV&gt;&lt;DIV class=""&gt;-8%&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98px" height="47px"&gt;2022-12-20&lt;/TD&gt;&lt;TD width="107.375px" height="47px"&gt;High&lt;/TD&gt;&lt;TD width="90px" height="47px"&gt;4&lt;/TD&gt;&lt;TD width="67.8021px" height="47px"&gt;3.25&lt;/TD&gt;&lt;TD width="129.49px" height="47px"&gt;19%&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98px" height="69px"&gt;2022-12-19&lt;/TD&gt;&lt;TD width="107.375px" height="69px"&gt;&lt;DIV class=""&gt;High&lt;/DIV&gt;&lt;DIV class=""&gt;Informational&lt;/DIV&gt;&lt;DIV class=""&gt;Medium&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="90px" height="69px"&gt;&lt;DIV class=""&gt;1&lt;/DIV&gt;&lt;DIV class=""&gt;2&lt;/DIV&gt;&lt;DIV class=""&gt;5&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.8021px" height="69px"&gt;&lt;DIV class=""&gt;2.00&lt;/DIV&gt;&lt;DIV class=""&gt;3.25&lt;/DIV&gt;&lt;DIV class=""&gt;3.67&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="129.49px" height="69px"&gt;&lt;DIV class=""&gt;-100%&lt;/DIV&gt;&lt;DIV class=""&gt;-62%&lt;/DIV&gt;&lt;DIV class=""&gt;27%&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;expected results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;_time severity AlertCount average change_percent&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="98.75px" height="25px"&gt;_time&lt;/TD&gt;&lt;TD width="107.375px" height="25px"&gt;&lt;DIV class=""&gt;severity&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.25px" height="25px"&gt;&lt;DIV class=""&gt;AlertCount&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="50.6146px" height="25px"&gt;&lt;DIV class=""&gt;average&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="100.396px" height="25px"&gt;&lt;DIV class=""&gt;change_percent&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98.75px" height="47px"&gt;2022-12-23&lt;/TD&gt;&lt;TD width="107.375px" height="47px"&gt;&lt;DIV class=""&gt;High&lt;/DIV&gt;&lt;DIV class=""&gt;Informational&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.25px" height="47px"&gt;&lt;DIV class=""&gt;3&lt;/DIV&gt;&lt;DIV class=""&gt;8&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="50.6146px" height="47px"&gt;&lt;DIV class=""&gt;3.25&lt;/DIV&gt;&lt;DIV class=""&gt;3.67&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="100.396px" height="47px"&gt;&lt;DIV class=""&gt;-22%&lt;/DIV&gt;&lt;DIV class=""&gt;59%&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98.75px" height="25px"&gt;2022-12-22&lt;/TD&gt;&lt;TD width="107.375px" height="25px"&gt;High&lt;/TD&gt;&lt;TD width="67.25px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="50.6146px" height="25px"&gt;3.25&lt;/TD&gt;&lt;TD width="100.396px" height="25px"&gt;-225%&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98.75px" height="47px"&gt;2022-12-21&lt;/TD&gt;&lt;TD width="107.375px" height="47px"&gt;&lt;DIV class=""&gt;High&lt;/DIV&gt;&lt;DIV class=""&gt;Informational&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.25px" height="47px"&gt;3&lt;/TD&gt;&lt;TD width="50.6146px" height="47px"&gt;&lt;DIV class=""&gt;3.25&lt;/DIV&gt;&lt;DIV class=""&gt;3.67&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="100.396px" height="47px"&gt;&lt;DIV class=""&gt;-8%&lt;/DIV&gt;&lt;DIV class=""&gt;-22%&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98.75px" height="25px"&gt;2022-12-20&lt;/TD&gt;&lt;TD width="107.375px" height="25px"&gt;High&lt;/TD&gt;&lt;TD width="67.25px" height="25px"&gt;4&lt;/TD&gt;&lt;TD width="50.6146px" height="25px"&gt;3.25&lt;/TD&gt;&lt;TD width="100.396px" height="25px"&gt;19%&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="98.75px" height="69px"&gt;2022-12-19&lt;/TD&gt;&lt;TD width="107.375px" height="69px"&gt;&lt;DIV class=""&gt;High&lt;/DIV&gt;&lt;DIV class=""&gt;Informational&lt;/DIV&gt;&lt;DIV class=""&gt;Medium&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="67.25px" height="69px"&gt;&lt;DIV class=""&gt;1&lt;/DIV&gt;&lt;DIV class=""&gt;2&lt;/DIV&gt;&lt;DIV class=""&gt;5&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="50.6146px" height="69px"&gt;&lt;DIV class=""&gt;3.25&lt;/DIV&gt;&lt;DIV class=""&gt;3.67&lt;/DIV&gt;&lt;DIV class=""&gt;2.00&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="100.396px" height="69px"&gt;&lt;DIV class=""&gt;-225%&lt;/DIV&gt;&lt;DIV class=""&gt;-83,5%&lt;/DIV&gt;&lt;DIV class=""&gt;60%&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 23 Dec 2022 16:38:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multivalue-field-not-ordered-properly/m-p/625188#M217331</guid>
      <dc:creator>Dantuzzo</dc:creator>
      <dc:date>2022-12-23T16:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: multivalue field not ordered properly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multivalue-field-not-ordered-properly/m-p/625200#M217334</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;values&lt;/FONT&gt; function returns values in lexicographical order with no attempts made to retain any associations to other fields.&amp;nbsp; The &lt;FONT face="courier new,courier"&gt;mvsort&lt;/FONT&gt; function won't help because it sorts the values the exact same way.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2022 00:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multivalue-field-not-ordered-properly/m-p/625200#M217334</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-24T00:06:17Z</dc:date>
    </item>
  </channel>
</rss>

