Hi @jip31,
to sort time fields you have to convert them in epochtime.
In your case, _time is already in epochtime so you have only to change the order of your commands:
| sort -_time
| eval "Event time" = strftime(_time, "%m/%d/%Y %H:%M")
| table "Event time"
Ciao.
Giuseppe
Hi @jip31,
to sort time fields you have to convert them in epochtime.
In your case, _time is already in epochtime so you have only to change the order of your commands:
| sort -_time
| eval "Event time" = strftime(_time, "%m/%d/%Y %H:%M")
| table "Event time"
Ciao.
Giuseppe
Thanks Giuseppe