Splunk Search

How do I use the reverse command to change the order of my table?

ckunath
Communicator

Hello,

I currently have a table that is ordered by time, ascending. It looks like this:

Date | Action
9pm  | Order finished
8pm  | Processing order step 3
8pm  | Processing order step 2
8pm  | Processing order step 1
7pm  | Start processing order

When I try to sort by time descending, I however get this:

Date | Action
7pm  | Start processing order
8pm  | Processing order step 3
8pm  | Processing order step 2
8pm  | Processing order step 1
9pm  | Order finished

As you can see, the events at 8pm did not change their order, therefore making it harder to read the table.
How can I correctly "turn the table around"? Any help is appreciated.

0 Karma
1 Solution

cmerriman
Super Champion

use |reverse to flip it the other way

View solution in original post

cmerriman
Super Champion

use |reverse to flip it the other way

ckunath
Communicator

Oh boy, i feel stupid for not finding it myself. Thank you!

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...