Refine your search:

I just ran a search that returned approximately 1 million results. Only after it completed (which took a bit longer than I'd anticipated), did I realize that I wanted the results sorted differently. So when I went to reverse the results (actually added a '-' to my sort) Splunk reran the search. The events have already been found, is there anyway to reverse/reorder them in place without rerunning the whole search?

asked 30 Sep '10, 13:43

thepocketwade's gravatar image

thepocketwade
1658
accept rate: 0%


One Answer:

You can click on the field you want sort by in the results - not sure if that's what you were looking for.

link

answered 30 Sep '10, 14:16

Brian%20Osburn's gravatar image

Brian Osburn
2.8k14
accept rate: 22%

oh, sure enough. I've never noticed that before.

(30 Sep '10, 14:24) thepocketwade
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×1,090
×36

Asked: 30 Sep '10, 13:43

Seen: 322 times

Last updated: 30 Sep '10, 14:16

Copyright © 2005-2012 Splunk, Inc. All rights reserved.