Splunk Search
Highlighted

Timeformat not sorting properly

Motivator

I am using this search:

sourcetype="foo" name="foobar*" | convert timeformat="%m/%d/%Y - %a" ctime(_time) AS Date | convert timeformat="%H:%M:%S.%N" ctime(_time) AS Time | table Time Date host name category | rename host as Server name as Name category as Category | sort - Time

The sort is not working. can anyone suggest what it is I am doing wrong with the sort or timeformat and how to fix it???

Tags (3)
0 Karma
Highlighted

Re: Timeformat not sorting properly

Explorer

Maybe I'm wrong but should it work if :

sourcetype="foo" name="foobar*" | convert timeformat="%m/%d/%Y - %a" ctime(time) AS Date | convert timeformat="%H:%M:%S.%N" ctime(time) AS Time | sort - Time | table Time Date host name category | rename host as Server name as Name category as Category

0 Karma
Highlighted

Re: Timeformat not sorting properly

Motivator

this works for | sort Time |
it does not work for | sort - Time |

I can use it though. please put it in as an answer so I can give you credit for the answer

0 Karma
Highlighted

Re: Timeformat not sorting properly

Motivator

Nope sorry this does not work in the search. Thanks

0 Karma
Highlighted

Re: Timeformat not sorting properly

Motivator

I figured it out. Timestamps is just a number before you convert the format so it sorts correctly so you need to sort t=he time before you convert the format like this.

sourcetype="foo" name="foobar*" | sort - _time | convert timeformat="%m/%d/%Y - %a" ctime(time) AS Date | convert timeformat="%H:%M:%S.%N" ctime(time) AS Time | table Time Date host name category | rename host as Server name as Name category as Category

View solution in original post

0 Karma