With the below query I'm trying to sort dateTime by descending order but the sorting is not working, could someone please help me to identify the issue in the query .
hostname="alt*" [search "Starting Batch job" AND hostname="alt*" UUID=* | stats values(UUID) as uuid by UUID | fields UUID] | regex "JOB Execution*" |stats values(@timestamp) as dateTime,values(UUID) as uuid,values(message) as message | sort - dateTime | table dateTime, uuid, message
Your stats command as it stands returns a single row with 3 multi-value fields. If you want to be able to sort the dateTime field, you should separate it out into different rows, possibly by moving the values timestamp to a by clause