Two-level sort

(Bud B) #1

I'm trying to overcome the issue that logstash/elasticsearch will not store dates with microsecond resolution. In logstash, I've parsed the micosecond part of my timestamp and put it in a separate field (log_usec). In kibana, I'd like to now do a two-level sort -- first by timestamp, then by log_usec. Is this possible?

Closest I've come is based on a hint from here:



in my query URL gets close. The only issue is that the @timestamp is sorted descending and the log_usec is sorted ascending. Thanks for any help with this. -- Bud

(Spencer Alger) #2

Not yet, check out

(Bud B) #3

Thanks. I was hoping I was missing something... -- Bud

(system) #4