Splunk Search

How can I control the order of results on a chart or timechart?

Communicator

I have a timechart that is based on count by score, where score is a whole number between 0 and 10. Every time I make a chart, the order shows up as:

0
1
10
2
3
...

I've tried sorting the results by score, but 10 never appears at the end of the results. I tried to use covert num(score) and sort the results but 10 is still showing up between 1 and 2 instead of at the end of the results.

What am I doing wrong?

Thx.

Tags (1)

Splunk Employee
Splunk Employee

It appears that even if you force score to a numeric value, the sort is always calculated as if the values are strings. This causes the 10 to order between 1 and 2, rather than after 9. Even when using | sort - num(score). I've filed a support ticket.

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!