Getting Data In

Sort asc/desc multivalue field

anonuser
Explorer

I have 2 multi value fields - script and instance. I joined them in another multi value field (steps) using mvappend

I would like to order the values from this new field called steps in asc order

I found mvsort, but it only works for alphabetic order, not chronological order

Labels (2)
Tags (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Are they all dates/times? Do you need to convert them to epoch times (strptime) before creating the new mv field, and then sort them as numbers. You can convert them back to strings (strftime) after sorting.

0 Karma

anonuser
Explorer

no, script and instance are actually file names... the idea is sort them in a chronological order based on _time

just to give more context, I'm seeing a list of files executions which has a lot of steps, each execution has a number and for each execution I can have more than 1 script or instance. Since I'm using transaction to collect all the events associated to the same execution, the fields script and instance are now multivalue fields

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you sort before any grouping then use stats list(script) list(instance) by id instead of using transaction? Sorry to be so vague but a more detailed example from you might help us help you.

0 Karma

anonuser
Explorer

sprry for not providing more information before!

Actually I just added the time into the messages and extracted them using regex. after doing a sort

tks!

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...