Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why are events not sorting in Chronological Order with a basic search?

$
0
0
Today, I noticed that, when performing a basic search, the events are not sorted chronologically. Additionally, not all events 'match up' correctly to the timeline. I have not found any other posts which document this strange behavior. With a simple `| sort _time`, the events sort as expected and correlate to the timeline accurately. The deployment was upgraded from 7.0.2 to 7.1.2 one week ago. Here's some screenshots that show the behavior: ![Events not in Chronological Order][1] ![Events not Correlated with Timeline][2] Does anyone have any ideas how to fix this issue? [1]: /storage/temp/255882-searcheventsoutoforder.png [2]: /storage/temp/255884-eventsnotmatchingtimeline.png

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>