- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PFB the search query that I am using for my panel. PFA the view of th dashboard as well.
index=scampservices OSIT4 sourcetype=RA* OR sourcetype=RIM* OR sourcetype=LMLo*| rex "(?ms)(?.?)\" | rex "(?ms)(?.?)\" | rex "^(?P\d+\s+\w+\s+\d+\s+\d+:\d+:\d+)" | rex "(?ms).(?.?)\" | rex "^(?:[^-\n]-){5}(?P\d+)" | rex "^(?:[^-\n]-){5}(?P[^ ]+)" | rex "[\s][TransactionD:][\s\n][#=]+[\n](?.?)[-#]+\n" | rex "[\s]Data:[\s\n][=]+\n*(?.?)[\s]-" | eval Status=coalesce(RIMStatus, RAStatus) | stats values(JobIDThread) as JobIDThread values(Status) as Status values(Resource) as Resource values(Timestamp) as Timestamp values(SoapAction) as SoapAction values(Consumer) as Consumer values(sourcetype) as ESFComponent by JobID | search Resource=$Resource_Email$
The Status values are being displayed sorted in alphabetical order. I want to sort them according to the JobThreadID values.
Kindly help.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does | sort JobThreadID
not work?
Edit:
You have multiple fields that are multivalue in a single event. This means that JobThreadID isn't necessarily related to the other values in the other fields that appear to be on the same line. You'll have to do something different in your search if you want to know which other values relate to JobThreadID.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does | sort JobThreadID
not work?
Edit:
You have multiple fields that are multivalue in a single event. This means that JobThreadID isn't necessarily related to the other values in the other fields that appear to be on the same line. You'll have to do something different in your search if you want to know which other values relate to JobThreadID.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, it doesn't. It's sorting the rows depending on the JobIDThread, not the Status field.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As a workaround, I concatenated the JobIDThread with the Status 🙂
