Home
Join the Community
Welcome Center
Welcome Center
Join Slack
Be a Splunk Champion
SplunkTrust
Splunk MVP
Become a User Group Leader
Splunk Love
Share a Tip
Find Answers
Splunk Administration
Getting Data In
Deployment Architecture
Monitoring Splunk
Using Splunk
Splunk Search
Dashboards & Visualizations
Splunk Products
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud Platform
Splunk Observability Cloud
Splunk AppDynamics
Splunk SOAR
Apps & Add-ons
All Apps and Add-ons
Splunk Development
Events
User Groups
Tech Talks: Technical Deep Dives
Office Hours: Ask the Experts
From Data to Insight: The Splunk Dashboard Contest
Dashboard Contest Terms and Conditions
Blogs
Community Blog
Product News & Announcements
Training & Certification Blog
Learning
Learning Paths
Training & Certification
Training + Certification Discussions
AppDynamics Knowledge Base
Best of conf
Resources
.conf25
Splunkbase
Developers
Documentation
Splunk Ideas
Splunk Events
Voice of Customer
Sign In
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Show
only
|
Search instead for
Did you mean:
Splunk Search
×
Join the Conversation
Without signing in, you're just watching from the sidelines.
Sign in or Register
to connect, share, and be part of the Splunk Community.
Ask a Question
Find Answers
:
Using Splunk
:
Splunk Search
:
How to sort the count
Options
Subscribe to RSS Feed
Mark Topic as New
Mark Topic as Read
Float this Topic for Current User
Bookmark Topic
Subscribe to Topic
Mute Topic
Printer Friendly Page
Mark as New
Bookmark Message
Subscribe to Message
Mute Message
Subscribe to RSS Feed
Permalink
Print
Report Inappropriate Content
How to sort the count
ajees_basha
Explorer
02-17-2021
06:30 PM
Labels
(7)
Labels
Labels:
chart
count
eval
join
stats
table
timechart
0
Karma
Reply
All forum topics
Previous Topic
Next Topic
Mark as New
Bookmark Message
Subscribe to Message
Mute Message
Subscribe to RSS Feed
Permalink
Print
Report Inappropriate Content
scelikok
SplunkTrust
02-17-2021
08:55 PM
Hi
@ajees_basha
,
You can use mvsort function;
| eval COUNT=mvsort(COUNT)
If this reply helps you an upvote and "Accept as Solution" is appreciated.
1
Karma
Reply
Post Reply
Got questions? Get answers!
Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!
Join Slack
Meet up IRL or virtually!
Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.
Find a Group
Related Topics
How to sort the counts of the sub-category items in the categories?
How to sort search and get rid of the count from LAST_MODIFIED_DATE and have them shown by ACTUAL_START_DATE?
How to generate a search to sort based on domain names and count the number of emails from the domain?
Get Updates on the Splunk Community!
Observability Simplified: Combining User Experience, Application Performance & ...
Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...
Event Series May & June: From Network Visibility to Service Intelligence
Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...
Global Splunk User Group Events: May + June 2026
Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide Staying ahead in the fast-paced ...
Read our Community Blog >