# Sort in a Data Table

**URL:** <https://discuss.elastic.co/t/sort-in-a-data-table/58992>\
**Category:** Kibana\
**Created:** [August 25, 2016, 11:59pm UTC](https://discuss.elastic.co/t/sort-in-a-data-table/58992 "2016-08-25T23:59:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![datadude](https://avatars.discourse-cdn.com/v4/letter/d/58f4c7/32.png) [@datadude](https://discuss.elastic.co/u/datadude)\
**Post date:** [August 25, 2016, 11:59pm UTC](https://discuss.elastic.co/t/sort-in-a-data-table/58992/1 "2016-08-25T23:59:46Z")

</div>

Lets say I use count as the metric,

Then I use said count as the sort metric in a data table this sort metric is used for all of the buckets/sub-buckets.

Should I be able to reasonably expect that the lines returned would be sorted from high to low since I am also selecting descending order?

I am not seeing it sorted in that manor I then click on the count heading to resort and it eventually gets to that but shouldn't it do that from the beginning?

Here is the request from Kibana:

{  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"analyze\_wildcard": true,  
"query": "Action: deny AND FirewallDomain: abcpf\* AND Type: TRAFFIC"  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gte": 1472082814725,  
"lte": 1472169214726,  
"format": "epoch\_millis"  
}  
}  
}  
],  
"must\_not": []  
}  
}  
}  
},  
"size": 0,  
"aggs": {  
"5": {  
"date\_range": {  
"field": "@timestamp",  
"ranges": [  
{  
"from": "now-23h-59m",  
"to": "now"  
}  
]  
},  
"aggs": {  
"3": {  
"terms": {  
"field": "SourceAddress",  
"size": 0,  
"order": {  
"\_count": "desc"  
}  
},  
"aggs": {  
"4": {  
"terms": {  
"field": "SourcePort",  
"size": 0,  
"order": {  
"\_count": "desc"  
}  
},  
"aggs": {  
"6": {  
"terms": {  
"field": "DestinationAddress",  
"size": 0,  
"order": {  
"\_count": "desc"  
}  
},  
"aggs": {  
"7": {  
"terms": {  
"field": "DestinationPort",  
"size": 0,  
"order": {  
"\_count": "desc"  
}  
},  
"aggs": {  
"8": {  
"terms": {  
"field": "IPProtocol",  
"size": 0,  
"order": {  
"\_count": "desc"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [August 26, 2016, 11:54pm UTC](https://discuss.elastic.co/t/sort-in-a-data-table/58992/2 "2016-08-26T23:54:21Z")

</div>

According to the posted request, the documents should be ordered by their doc `_count`. If you inspect the response you should see this is the case. If you are seeing something different, please post the response and the generated table.

Here is the supporting documentation for count in term aggregations: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-order](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-order)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/sort-in-a-data-table/58992/3 "2017-07-06T13:40:11Z")

</div>


