Getting Data In

Sort asc/desc multivalue field

anonuser
Explorer

I have 2 multi value fields - script and instance. I joined them in another multi value field (steps) using mvappend

I would like to order the values from this new field called steps in asc order

I found mvsort, but it only works for alphabetic order, not chronological order

Labels (1)
Tags (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Are they all dates/times? Do you need to convert them to epoch times (strptime) before creating the new mv field, and then sort them as numbers. You can convert them back to strings (strftime) after sorting.

0 Karma

anonuser
Explorer

no, script and instance are actually file names... the idea is sort them in a chronological order based on _time

just to give more context, I'm seeing a list of files executions which has a lot of steps, each execution has a number and for each execution I can have more than 1 script or instance. Since I'm using transaction to collect all the events associated to the same execution, the fields script and instance are now multivalue fields

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you sort before any grouping then use stats list(script) list(instance) by id instead of using transaction? Sorry to be so vague but a more detailed example from you might help us help you.

0 Karma

anonuser
Explorer

sprry for not providing more information before!

Actually I just added the time into the messages and extracted them using regex. after doing a sort

tks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...