Splunk Search

How to display column results in descending order?

prannoy93singh
Engager

It shows the result in the below format

uri          208         400  
...            ....             ...

I want to show those uri's on top which has maximum responseCodes, I tried using the below query but it is not giving the desired output.

host="*prod*" uri="*v*" earliest = -7d@d
| WHERE responseCode != 200 
| chart count by uri, responseCode
| sort -responseCode

Sort is not giving results in descending order.

0 Karma
1 Solution

pruthvikrishnap
Contributor

Hi Prannoy,

Try adding desc in your search, please try the one below.

host="prod" uri="v" earliest = -7d@d
| WHERE responseCode != 200
| chart count by uri, responseCode
| sort responseCode desc

Let me know if it helps.

View solution in original post

0 Karma

pruthvikrishnap
Contributor

Hi Prannoy,

Try adding desc in your search, please try the one below.

host="prod" uri="v" earliest = -7d@d
| WHERE responseCode != 200
| chart count by uri, responseCode
| sort responseCode desc

Let me know if it helps.

0 Karma

prannoy93singh
Engager

I tried implementing it, but still I am not getting the desired result.
I was thinking to do the sum of columns and then sort the sum, but am not able to implement it effectively.

0 Karma

Sukisen1981
Champion

hmm what happens if you try this <your query>| addtotals | sort - Total

0 Karma

arunrajamani
New Member

Hello,
Am facing similar kind of issue where i need to sort the time column with the latest time.
Will sorting works with column header time value using chart command?

0 Karma

prannoy93singh
Engager

yes, it is working.
Thank You 🙂

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...