Splunk Search

Manipulate results without re-running search

Path Finder

I just ran a search that returned approximately 1 million results. Only after it completed (which took a bit longer than I'd anticipated), did I realize that I wanted the results sorted differently. So when I went to reverse the results (actually added a '-' to my sort) Splunk reran the search. The events have already been found, is there anyway to reverse/reorder them in place without rerunning the whole search?

1 Solution

Builder

You can click on the field you want sort by in the results - not sure if that's what you were looking for.

View solution in original post

Builder

You can click on the field you want sort by in the results - not sure if that's what you were looking for.

View solution in original post

Path Finder

oh, sure enough. I've never noticed that before.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!