<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to sort based on multiple columns in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657880#M227238</link>
    <description>&lt;P&gt;What is not correct about the StartTime and EndTime fields?&amp;nbsp; What do you expect them to be?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 12:20:54 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-09-18T12:20:54Z</dc:date>
    <item>
      <title>How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657874#M227235</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Below is my query&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")|head 7
| eval EBNCStatus="ebnc event balanced successfully"
| table EBNCStatus True ]
|rename busDt as Business_Date
|rename fileName as File_Name
|rename CARS.UNB_Duration as CARS.UNB_Duration(Minutes)
|table Business_Date File_Name StartTime EndTime CARS.UNB_Duration(Minutes) Records totalClosingBal totalRecordsWritten totalRecords EBNCStatus
|sort -Business_Date&lt;/LI-CODE&gt;&lt;P&gt;I am sorting on the basis of business date but my startTime and EndTime is not coming correct.&lt;/P&gt;&lt;P&gt;Can someone guide me&lt;/P&gt;&lt;P&gt;Below is the screenshot for the same&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aditsss_0-1695034960654.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27223i98A619B29F11285D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aditsss_0-1695034960654.png" alt="aditsss_0-1695034960654.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 12:16:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657874#M227235</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-18T12:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657880#M227238</link>
      <description>&lt;P&gt;What is not correct about the StartTime and EndTime fields?&amp;nbsp; What do you expect them to be?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 12:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657880#M227238</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-18T12:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657883#M227239</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there's something wrong in this search because there's a square parenthesis close but not the open, could you share the correct search?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 12:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657883#M227239</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-18T12:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657965#M227266</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the query&lt;/P&gt;&lt;P&gt;search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")|head 7&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully"&lt;BR /&gt;| table EBNCStatus True&lt;BR /&gt;|rename busDt as Business_Date&lt;BR /&gt;|rename fileName as File_Name&lt;BR /&gt;|rename CARS.UNB_Duration as CARS.UNB_Duration(Minutes)&lt;BR /&gt;|table Business_Date File_Name StartTime EndTime CARS.UNB_Duration(Minutes) Records totalClosingBal totalRecordsWritten totalRecords EBNCStatus&lt;BR /&gt;|sort -Business_Date&lt;/P&gt;&lt;P&gt;The issue I am facing is when I am sorting with -businessDate&amp;nbsp; businessDate is coming correct but startTime AND EndTime is not coming correct&lt;/P&gt;&lt;P&gt;For example in below screenshot for BusinessDate 09/11 startTime and EndTime is coming as 09/13 it should be 09/12.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aditsss_0-1695115824267.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27230iF76B36C3AEBE4AB9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aditsss_0-1695115824267.png" alt="aditsss_0-1695115824267.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;please guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 09:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657965#M227266</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-19T09:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657966#M227267</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;is it correct the "&lt;SPAN&gt;|head 7" in the second row?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyway, did you checked the data in the events?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;you used the table command that doesn't group any data and only display them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It seemes that you have wrong data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 09:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657966#M227267</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-19T09:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657977#M227269</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I used Group By command here .Can you please guide.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657977#M227269</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-19T10:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to sort based on multiple columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657979#M227270</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you have to use a common key to group events:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")|head 7
| eval 
   EBNCStatus="ebnc event balanced successfully",
   StartTime=strptime(StartTime,"%Y-%m-%d %H:%M:%S.%3N"),
   EndTime=strptime(EndTime,"%Y-%m-%d %H:%M:%S.%3N")
| rename 
   busDt as Business_Date
   fileName as File_Name
   CARS.UNB_Duration as CARS.UNB_Duration(Minutes)
| stats 
   earliest(StartTime) AS StartTime
   latest(EndTime) AS EndTime
   values("CARS.UNB_Duration(Minutes)") AS "CARS.UNB_Duration(Minutes)"
   values(Records) AS Records 
   values(totalClosingBal) AS totalClosingBal
   values(totalRecordsWritten) AS totalRecordsWritten
   values(totalRecords) AS totalRecords
   values(EBNCStatus) AS EBNCStatus
   BY Business_Date File_Name
| eval 
   StartTime=strftime(StartTime,"%Y-%m-%d %H:%M:%S.%3N"),
   EndTime=strftime(EndTime,"%Y-%m-%d %H:%M:%S.%3N")
| sort -Business_Date&lt;/LI-CODE&gt;&lt;P&gt;if you have more values for the other fields, you can use other functions as last or first.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sort-based-on-multiple-columns/m-p/657979#M227270</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-19T10:33:33Z</dc:date>
    </item>
  </channel>
</rss>

