Splunk Search

How to sort by max value of a dynamic set of columns

dbendixen
Explorer

I have a Splunk query that shows a count of error codes by software version. The table looks something like this:

Error Code      1.1     1.2     1.3
Error 1         5       0       10
Error 2         7       9       0
Error 3         20      3       8

What I'd like to do is dynamically find the column with the max value across all columns and sort descending on that column. Is that even possible?

Tags (4)
0 Karma

somesoni2
Revered Legend

Try this (may be inefficient) workaround

"Your  base search giving you output in Above format" | table [search "Your  base search giving you output in Above format" | untable "Error Code" SoftwareVersion Count | stats max(Count) as count by SoftwareVersion | sort 0 - count | stats list(SoftwareVersion) as search | nomv search] 

dbendixen
Explorer

I will give this a try, thanks!

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...