Deployment Architecture

Can the search sort events order so that you always get them in reverse chronological order?

romedome
Path Finder

In my years of Splunking I recall that you could not rely on events arriving in synchronous order 100% of the time. Rather, you will get them as the Search Head receives them based on how fast or slow the indexers are. This, in turn, means that you can't rely on first() or last() on giving you the earliest or latest value of a field. You'll only see this happen once in a blue moon, but it can happen. The problem is I can't find the original documentation that stated this issue.
My friend, on the other hand, says that the search head sorts events so that you always get them in reverse chronological order because he's never seen the opposite happen.

Who's right?

0 Karma

kmaron
Motivator

according to Splunk Docs here: http://docs.splunk.com/Documentation/Splunk/7.0.3/SearchTutorial/Startsearching

By default, the events appear as a list that is ordered starting with the most recent event.

0 Karma

romedome
Path Finder

Right, but are there scenarios that cause the default ordering to break?

0 Karma

kmaron
Motivator

This is old so it may not apply anymore but you might find it pertains

https://answers.splunk.com/answers/246691/search-head-not-consistently-ordering-results-from.html

0 Karma

romedome
Path Finder

Yes, his question pertains to mine. Wish I could find something official.
Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...