Splunk Search

How to sort by max value of a dynamic set of columns

dbendixen
Explorer

I have a Splunk query that shows a count of error codes by software version. The table looks something like this:

Error Code      1.1     1.2     1.3
Error 1         5       0       10
Error 2         7       9       0
Error 3         20      3       8

What I'd like to do is dynamically find the column with the max value across all columns and sort descending on that column. Is that even possible?

Tags (4)
0 Karma

somesoni2
Revered Legend

Try this (may be inefficient) workaround

"Your  base search giving you output in Above format" | table [search "Your  base search giving you output in Above format" | untable "Error Code" SoftwareVersion Count | stats max(Count) as count by SoftwareVersion | sort 0 - count | stats list(SoftwareVersion) as search | nomv search] 

dbendixen
Explorer

I will give this a try, thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...