- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
andras_kerekes
Explorer
05-09-2013
01:37 PM
I use Splunk 5.0.2 with Java SDK 1.1.
I've noticed that the results of a search are sorted according to the _time field. Is it possible to change this default ordering?
I know I can use the sort command to sort on fields I want, what I'd like to know if there is a global configuration option I can use to change the default ordering.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ayn
Legend
05-09-2013
01:42 PM
No, the way Splunk's search works is that it finds events in reverse chronological order, so no other default sort order is available.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ayn
Legend
05-09-2013
01:42 PM
No, the way Splunk's search works is that it finds events in reverse chronological order, so no other default sort order is available.
