Hi, simply put a sort command behind your search something like this:
... | sort column_name
you can control desc order with a minus:
... | sort -column_name
Thank you. Exactly what I needed.
One column ranked by priority (Asc), the other by the length of the event (desc)
Maybe i don't understand what your problem is, but for me, this is what it does.
It doesn't work for me this is my query
<query>index=aut_kpi2 $servicesToken$ $catalogToken$ $subscriptionToken$ | timechart span=$spanToken$ count by service_offering_name</query> <earliest>$timeToken.earliest$</earliest> <latest>$timeToken.latest$</latest
You used timechart, which is used to calculate values over time buckets. You cant reorder the time, it makes no sense. Take stats instead of timechart.