Splunk Search

Move _time to the last column in the attached mail

rayar
Contributor

How I can move _time column to be the last on the an attached csv file in the email send by scheduled report

the query returns the _time as the last column but in the attached mail it's set as a fist column

the query

.
.
.
| table USER_ID duser FIRST_NAME LAST_NAME Duration cn1 _time
| rename cn1 as "Duration (sec)", FIRST_NAME as "First Name", LAST_NAME as "Last Name"
| search "First Name"="" AND "Last Name"=""
| outputcsv vpn_data.csv

0 Karma

anmolpatel
Builder

@rayar as per the doc for output command, it adds the _time field to the front.
https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Outputcsv#Internal_fields_a...

if you want to have the strict order, here is a workaround:

| rename cn1 as "Duration (sec)", FIRST_NAME as "First Name", LAST_NAME as "Last Name"
| search "First Name"="" AND "Last Name"=""
| eval time = strftime(_time, "%Y-%d-%m %H:%M:%S")
| fields USER_ID duser "First Name" "Last Name" Duration "Duration (sec)" time
| outputcsv vpn_data.csv

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...