Splunk Search

How can I sort field values depending on the another field values ?

varun99
Path Finder

alt textPFB the search query that I am using for my panel. PFA the view of th dashboard as well.

index=scampservices OSIT4 sourcetype=RA* OR sourcetype=RIM* OR sourcetype=LMLo*| rex "(?ms)(?.?)\" | rex "(?ms)(?.?)\" | rex "^(?P\d+\s+\w+\s+\d+\s+\d+:\d+:\d+)" | rex "(?ms).(?.?)\" | rex "^(?:[^-\n]-){5}(?P\d+)" | rex "^(?:[^-\n]-){5}(?P[^ ]+)" | rex "[\s][TransactionD:][\s\n][#=]+[\n](?.?)[-#]+\n" | rex "[\s]Data:[\s\n][=]+\n*(?.?)[\s]-" | eval Status=coalesce(RIMStatus, RAStatus) | stats values(JobIDThread) as JobIDThread values(Status) as Status values(Resource) as Resource values(Timestamp) as Timestamp values(SoapAction) as SoapAction values(Consumer) as Consumer values(sourcetype) as ESFComponent by JobID | search Resource=$Resource_Email$

The Status values are being displayed sorted in alphabetical order. I want to sort them according to the JobThreadID values.
Kindly help.

0 Karma
1 Solution

micahkemp
Champion

Does | sort JobThreadID not work?

Edit:

You have multiple fields that are multivalue in a single event. This means that JobThreadID isn't necessarily related to the other values in the other fields that appear to be on the same line. You'll have to do something different in your search if you want to know which other values relate to JobThreadID.

View solution in original post

0 Karma

micahkemp
Champion

Does | sort JobThreadID not work?

Edit:

You have multiple fields that are multivalue in a single event. This means that JobThreadID isn't necessarily related to the other values in the other fields that appear to be on the same line. You'll have to do something different in your search if you want to know which other values relate to JobThreadID.

0 Karma

varun99
Path Finder

No, it doesn't. It's sorting the rows depending on the JobIDThread, not the Status field.

0 Karma

varun99
Path Finder

As a workaround, I concatenated the JobIDThread with the Status 🙂

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...