Dashboards & Visualizations

How to have a results table always display newest events first, even with real-time searches?

Ayn
Legend

I've built a search form using basic XML, which displays results in a few different ways, among others a results table. I would like to be able to use this form as a real-time dashboard, which works just fine except for that the events in the results table will be displayed as oldest first. Using reverse fixes that in the real-time case, however that has the undesired effect on non-real-time searches that events are displayed in oldest-to-newest order instead. I also understand using reverse has a considerable impact on performance. Is there a way to have the results table always show newest events first, either using simple or advanced XML?

0 Karma
1 Solution

ziegfried
Influencer

This will sort the events/results in descending order of their time:

... | sort -_time

where as this one would sort them in descending order of the time they have been indexed:

... | sort -_indextime

View solution in original post

Ayn
Legend

The search itself is very simple. It uses a searchTemplate with the search 'sourcetype="squid" clientip="$clientip$" uri_host="$uri_host$"' and a searchPostProcess 'sort -_time'. The post processing made it work the way I wanted.

0 Karma

sideview
SplunkTrust
SplunkTrust

can you post the search you're using? I believe the SimpleResultsTable has code that attempts to show newest first even in real time search cases, and I suspect that somehow this default behavior is being subtly defeated.

0 Karma

ziegfried
Influencer

This will sort the events/results in descending order of their time:

... | sort -_time

where as this one would sort them in descending order of the time they have been indexed:

... | sort -_indextime
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...