Splunk Search

sorting in specific requirement

VI371887
Path Finder

Below is my data in tabular format I want

FUNCTION | HK | SG
AGE |107.773 | 120.644
Burg |49.206 | 37.6
COM | 12 | 61.778
RIO |56.803 |
STO | | 10.115

I wan the function field to be sorted to look like below.. as they come from different applications

FUNCTION | HK | SG
AGE |107.773 | 120.644
RIO |56.803 |
COM | 12 | 61.778
STO | | 10.115
Burg |49.206 | 37.6

I want to be able to show AGE, RIO and other filed under App A first then COM from Application B and then STO & Burg with the goal to have all of these Functions in same table.

is sit possible in splunk ?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@VI371887

Do you have application information in first table?? Can you please share that information also?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...