Getting Data In

Sort asc/desc multivalue field

anonuser
Explorer

I have 2 multi value fields - script and instance. I joined them in another multi value field (steps) using mvappend

I would like to order the values from this new field called steps in asc order

I found mvsort, but it only works for alphabetic order, not chronological order

Labels (1)
Tags (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Are they all dates/times? Do you need to convert them to epoch times (strptime) before creating the new mv field, and then sort them as numbers. You can convert them back to strings (strftime) after sorting.

0 Karma

anonuser
Explorer

no, script and instance are actually file names... the idea is sort them in a chronological order based on _time

just to give more context, I'm seeing a list of files executions which has a lot of steps, each execution has a number and for each execution I can have more than 1 script or instance. Since I'm using transaction to collect all the events associated to the same execution, the fields script and instance are now multivalue fields

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you sort before any grouping then use stats list(script) list(instance) by id instead of using transaction? Sorry to be so vague but a more detailed example from you might help us help you.

0 Karma

anonuser
Explorer

sprry for not providing more information before!

Actually I just added the time into the messages and extracted them using regex. after doing a sort

tks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...