Splunk Search

How to sort by max value of a dynamic set of columns

dbendixen
Explorer

I have a Splunk query that shows a count of error codes by software version. The table looks something like this:

Error Code      1.1     1.2     1.3
Error 1         5       0       10
Error 2         7       9       0
Error 3         20      3       8

What I'd like to do is dynamically find the column with the max value across all columns and sort descending on that column. Is that even possible?

Tags (4)
0 Karma

somesoni2
Revered Legend

Try this (may be inefficient) workaround

"Your  base search giving you output in Above format" | table [search "Your  base search giving you output in Above format" | untable "Error Code" SoftwareVersion Count | stats max(Count) as count by SoftwareVersion | sort 0 - count | stats list(SoftwareVersion) as search | nomv search] 

dbendixen
Explorer

I will give this a try, thanks!

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...