Splunk Search

How do I use the reverse command to change the order of my table?

ckunath
Communicator

Hello,

I currently have a table that is ordered by time, ascending. It looks like this:

Date | Action
9pm  | Order finished
8pm  | Processing order step 3
8pm  | Processing order step 2
8pm  | Processing order step 1
7pm  | Start processing order

When I try to sort by time descending, I however get this:

Date | Action
7pm  | Start processing order
8pm  | Processing order step 3
8pm  | Processing order step 2
8pm  | Processing order step 1
9pm  | Order finished

As you can see, the events at 8pm did not change their order, therefore making it harder to read the table.
How can I correctly "turn the table around"? Any help is appreciated.

0 Karma
1 Solution

cmerriman
Super Champion

use |reverse to flip it the other way

View solution in original post

cmerriman
Super Champion

use |reverse to flip it the other way

ckunath
Communicator

Oh boy, i feel stupid for not finding it myself. Thank you!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...