<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse time info in chart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706618#M239115</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Cool, your proposal does exactly what I was looking for.&lt;BR /&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 07:28:06 GMT</pubDate>
    <dc:creator>Ste</dc:creator>
    <dc:date>2024-12-12T07:28:06Z</dc:date>
    <item>
      <title>Reverse time info in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706545#M239086</link>
      <description>&lt;P&gt;Dear experts&lt;BR /&gt;&lt;BR /&gt;My search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" search_name="xyz" Umgebung="prod" earliest=-7d@d latest=@d zbpIdentifier IN (454-594, 256-14455, 453-12232)
| bin span=1d _time aligntime=@d
| stats count as myCount by _time, zbpIdentifier
| eval _time=strftime(_time,"%Y %m %d") 
| chart values(myCount) over zbpIdentifier by _time limit=0 useother=f&lt;/LI-CODE&gt;&lt;P&gt;produces the following chart:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ste_0-1733926591588.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33806iA6C3619F80629758/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ste_0-1733926591588.png" alt="Ste_0-1733926591588.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For each zbpIdentifier I have a group within the graph showing the number of messages during several days.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;How to change the order of the day values within the group? Green (yesterday) should be the most left, followed by pink (the day before yesterday) and orange, .....&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| reverse&lt;/LI-CODE&gt;&lt;P&gt;will change the order of the whole groups, that's not what I need.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;All kind of time sorting like&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| sort +"_time"
or
| sort -"_time"&lt;/LI-CODE&gt;&lt;P&gt;before and after&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| chart ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;does not change anything.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 14:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706545#M239086</guid>
      <dc:creator>Ste</dc:creator>
      <dc:date>2024-12-11T14:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse time info in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706563#M239089</link>
      <description>&lt;P&gt;Chart will put the columns in ascending order lexicographically. To get around this, you should use transpose, sort and transpose (back). Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| bin span=1d _time aligntime=@d
| stats count as myCount by _time, zbpIdentifier
| chart values(myCount) over zbpIdentifier by _time limit=0 useother=f
| transpose 0 column_name=date header_field=zbpIdentifier
| sort 0 -date
| eval date=strftime(date, "%Y %m %d")
| transpose 0 column_name==zbpIdentifier header_field=date&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 11 Dec 2024 16:00:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706563#M239089</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-12-11T16:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse time info in chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706618#M239115</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Cool, your proposal does exactly what I was looking for.&lt;BR /&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 07:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reverse-time-info-in-chart/m-p/706618#M239115</guid>
      <dc:creator>Ste</dc:creator>
      <dc:date>2024-12-12T07:28:06Z</dc:date>
    </item>
  </channel>
</rss>

