Splunk Search

Is there a way to reverse comparison order of week over week results using timewrap?

DaveAsh
Engager

I am using timewrap to return week over week results. I need to be able to change the order of comparison from week1, week2, week3 to show as week3, week2, week1. Is there a way to change the comparison order with timewrap?
Thanks.

0 Karma

ppablo
Retired

Hi @DaveAsh

Would you be able to use the reverse command to get what you need? You can try adding it to the end of your search like so:

... | reverse

Here's the documentation on the reverse command:
http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Reverse

0 Karma

ppablo
Retired

Ahh I see what you mean. I'm not very familiar with the Timewrap app as I haven't used it myself, but from looking at the images of the app on apps.splunk.com, you want to change the order of the legend on the right side?

0 Karma

DaveAsh
Engager

Thank you ppablo, While I tried reverse it doesn't do what I need. It does reverse the week, but the lay out is still the same. Lets say the colors returned from timewrap are blue-this week, yellow-last week, red-2 weeks ago, purple-3 weeks ago. I would like the results to be purple-3 weeks ago, red-2 weeks ago, yellow- last week, and blue- this week. Just changing the order of the weeks.

Does that make any better sense? Thanks.

0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...