Splunk Search

How do I make table header sort able?

jangid
Builder

I want to sort the data when I click to header for respective column?
How do I ?

Tags (2)
0 Karma

jangid
Builder

Another example
31 OCT 2012
26 NOV 2012
24 NOV 2012
23 NOV 2012
22 NOV 2012
21 NOV 2012
16 NOV 2012
01 NOV 2012

0 Karma

jangid
Builder

some of the cases
If

  1. fields contains time in seconds
    e.g. 00:00:15
    works with date/time

  2. Fields contains multivalue
    e.g.
    0 0 1 1
    1 1 2
    2 1 2

0 Karma

jonuwz
Influencer

I'm guessing fields with dates / times dont sort properly ? or is it something else ?

0 Karma

Ayn
Legend

This is default behaviour for results tables in Splunk - columns can be sorted on by clicking on them. Please tell us more about your specific situation, as you seem to be running some kind of non-standard setup for a results table...

0 Karma

jangid
Builder

Thanks, seems bug in splunk.

Its working on some fields but not all of them.

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...