Splunk Search
Highlighted

Move _time to the last column in the attached mail

Loves-to-Learn

How I can move _time column to be the last on the an attached csv file in the email send by scheduled report

the query returns the _time as the last column but in the attached mail it's set as a fist column

the query

.
.
.
| table USERID duser FIRSTNAME LASTNAME Duration cn1 _time
| rename cn1 as "Duration (sec)", FIRST
NAME as "First Name", LASTNAME as "Last Name"
| search "First Name"="" AND "Last Name"=""
| outputcsv vpn
data.csv

0 Karma
Highlighted

Re: Move _time to the last column in the attached mail

Builder

@rayar as per the doc for output command, it adds the time field to the front.
https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Outputcsv#Internal
fieldsandtheoutputcsvcommand

if you want to have the strict order, here is a workaround:

| rename cn1 as "Duration (sec)", FIRSTNAME as "First Name", LASTNAME as "Last Name"
| search "First Name"="" AND "Last Name"=""
| eval time = strftime(time, "%Y-%d-%m %H:%M:%S")
| fields USER
ID duser "First Name" "Last Name" Duration "Duration (sec)" time
| outputcsv vpn_data.csv

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.