Splunk Search

How to display column results in descending order?

prannoy93singh
Engager

It shows the result in the below format

uri          208         400  
...            ....             ...

I want to show those uri's on top which has maximum responseCodes, I tried using the below query but it is not giving the desired output.

host="*prod*" uri="*v*" earliest = -7d@d
| WHERE responseCode != 200 
| chart count by uri, responseCode
| sort -responseCode

Sort is not giving results in descending order.

0 Karma
1 Solution

pruthvikrishnap
Contributor

Hi Prannoy,

Try adding desc in your search, please try the one below.

host="prod" uri="v" earliest = -7d@d
| WHERE responseCode != 200
| chart count by uri, responseCode
| sort responseCode desc

Let me know if it helps.

View solution in original post

0 Karma

pruthvikrishnap
Contributor

Hi Prannoy,

Try adding desc in your search, please try the one below.

host="prod" uri="v" earliest = -7d@d
| WHERE responseCode != 200
| chart count by uri, responseCode
| sort responseCode desc

Let me know if it helps.

0 Karma

prannoy93singh
Engager

I tried implementing it, but still I am not getting the desired result.
I was thinking to do the sum of columns and then sort the sum, but am not able to implement it effectively.

0 Karma

Sukisen1981
Champion

hmm what happens if you try this <your query>| addtotals | sort - Total

0 Karma

arunrajamani
New Member

Hello,
Am facing similar kind of issue where i need to sort the time column with the latest time.
Will sorting works with column header time value using chart command?

0 Karma

prannoy93singh
Engager

yes, it is working.
Thank You 🙂

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...