Splunk Search

How to sort by max value of a dynamic set of columns

dbendixen
Explorer

I have a Splunk query that shows a count of error codes by software version. The table looks something like this:

Error Code      1.1     1.2     1.3
Error 1         5       0       10
Error 2         7       9       0
Error 3         20      3       8

What I'd like to do is dynamically find the column with the max value across all columns and sort descending on that column. Is that even possible?

Tags (4)
0 Karma

somesoni2
Revered Legend

Try this (may be inefficient) workaround

"Your  base search giving you output in Above format" | table [search "Your  base search giving you output in Above format" | untable "Error Code" SoftwareVersion Count | stats max(Count) as count by SoftwareVersion | sort 0 - count | stats list(SoftwareVersion) as search | nomv search] 

dbendixen
Explorer

I will give this a try, thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...