<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: show top 5 values in column chart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406138#M170876</link>
    <description>&lt;P&gt;@sarit_s,&lt;BR /&gt;
I don't see a link to the screenshot..&lt;/P&gt;

&lt;P&gt;Thanks .. &lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2019 12:01:19 GMT</pubDate>
    <dc:creator>Shan</dc:creator>
    <dc:date>2019-06-11T12:01:19Z</dc:date>
    <item>
      <title>show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406127#M170865</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
im trying to show top 5 values in column chart&lt;BR /&gt;
this is my query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="ssys_*_fdm"  pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
| `Region`
| `pauseReason`
|`SerialNumber`
| top 5 pause_reason SerialNumber
| table pause_reason SerialNumber
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but the chart is empty&lt;BR /&gt;
removing the table returns me SerialNumber and count in the chart which i don't want&lt;BR /&gt;
what am i doing wrong ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 07:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406127#M170865</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-06T07:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406128#M170866</link>
      <description>&lt;P&gt;What exactly do you want to display? The top 5 SerialNumber or the top 5 pause_reason or something else?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406128#M170866</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2019-06-06T08:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406129#M170867</link>
      <description>&lt;P&gt;top 5 SerialNumber and top 5 pause_reason&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406129#M170867</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-06T08:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406130#M170868</link>
      <description>&lt;P&gt;You could create two seperate columns charts; one for SerialNumber and one for pause_reason.&lt;/P&gt;

&lt;P&gt;Or do you want only one column chart for both? If so, what are the X axis and the Y axis supposed to be?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406130#M170868</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2019-06-06T08:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406131#M170869</link>
      <description>&lt;P&gt;i want one for both&lt;BR /&gt;
 X axis will be SerialNumber and Y axis will be pause_reason&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406131#M170869</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-06T08:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406132#M170870</link>
      <description>&lt;P&gt;I'm still confused. How do you determine which are the top 5 values?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406132#M170870</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2019-06-06T08:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406133#M170871</link>
      <description>&lt;P&gt;the 5 with the highest values per SerialNumber&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406133#M170871</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-06T08:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406134#M170872</link>
      <description>&lt;P&gt;Dear @sarit_s,&lt;/P&gt;

&lt;P&gt;Use below query and change index and by clause filed as per your need. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=*  pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
| stats count(pause_reason) as pause_reason , count(SerialNumber) as SerialNumber by sourcetype
| table sourcetype pause_reason SerialNumber
| sort  -pause_reason -SerialNumber limit=5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;While displaying in chart, choose Column chart so that both pause_reason SerialNumber top 5 values will be displayed.. &lt;/P&gt;

&lt;P&gt;you can try another approach also ..&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=*  pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
| stats count(pause_reason) as pause_reason , count(SerialNumber) as SerialNumber by sourcetype
| table sourcetype pause_reason SerialNumber
| top limit=5 sourcetype pause_reason SerialNumber
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks.. &lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 07:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406134#M170872</guid>
      <dc:creator>Shan</dc:creator>
      <dc:date>2019-06-11T07:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406135#M170873</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Thanks for your comment&lt;BR /&gt;
i need clause field to be by SerialNumber and since we are counting the SerialNumber in stats it is not possible to have it in clause field&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 08:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406135#M170873</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-11T08:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406136#M170874</link>
      <description>&lt;P&gt;@sarit_s ,&lt;/P&gt;

&lt;P&gt;Can you display the output format. which you need to achieve ..&lt;/P&gt;

&lt;P&gt;Thanks ..&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 09:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406136#M170874</guid>
      <dc:creator>Shan</dc:creator>
      <dc:date>2019-06-11T09:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406137#M170875</link>
      <description>&lt;P&gt;&lt;IMG src="https://imgur.com/AjrEGtc" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;this is a link to the screenshot&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 09:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406137#M170875</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-11T09:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406138#M170876</link>
      <description>&lt;P&gt;@sarit_s,&lt;BR /&gt;
I don't see a link to the screenshot..&lt;/P&gt;

&lt;P&gt;Thanks .. &lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 12:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406138#M170876</guid>
      <dc:creator>Shan</dc:creator>
      <dc:date>2019-06-11T12:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406139#M170877</link>
      <description>&lt;P&gt;&lt;A href="https://imgur.com/AjrEGtc"&gt;https://imgur.com/AjrEGtc&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 12:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406139#M170877</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-11T12:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406140#M170878</link>
      <description>&lt;P&gt;do you have any idea?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 12:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406140#M170878</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-12T12:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406141#M170879</link>
      <description>&lt;P&gt;i want to update my question&lt;BR /&gt;
i want to display graph that showing top 5 SerialNumbers for top 5 pause_reasons..&lt;/P&gt;

&lt;P&gt;i got this query &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=ssys_*_fdm  pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
| `SerialNumber`
| `pauseReason`

|stats count by SerialNumber,pause_reason
|sort -count 
|stats list(pause_reason) as pause_reason,  count by SerialNumber
|sort -count | head 5
| fields SerialNumber,pause_reason
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;this query gives me the desired result in table but the chart is empty&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 12:24:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406141#M170879</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-12T12:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406142#M170880</link>
      <description>&lt;P&gt;Hi @sarit_s,&lt;/P&gt;

&lt;P&gt;Have a look here for sorting based on two terms : &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/246476/how-to-sort-a-table-based-on-two-columns-in-order.html"&gt;https://answers.splunk.com/answers/246476/how-to-sort-a-table-based-on-two-columns-in-order.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So you're really close to the answer, it should be like this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=ssys_*_fdm  pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
 | `SerialNumber`
 | `pauseReason`
 |stats count by SerialNumber,pause_reason
 |sort 5 -count 
 |stats list(pause_reason) as pause_reason,  count by SerialNumber
 |sort 5 -count
 | fields SerialNumber,pause_reason, count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this works out for you.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2019 19:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406142#M170880</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-16T19:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406143#M170881</link>
      <description>&lt;P&gt;You are making this WAY too hard.  It is simply this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="ssys_*_fdm" pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
| `Region`
| `pauseReason`
| `SerialNumber`
| top 5 pause_reason BY SerialNumber
| table pause_reason SerialNumber
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 16 Jun 2019 22:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406143#M170881</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-06-16T22:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406144#M170882</link>
      <description>&lt;P&gt;thanks&lt;BR /&gt;
i finally did it that way :&lt;BR /&gt;
    (index=ssys_*_fdm OR index=other_fdm) pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" &lt;BR /&gt;
    | &lt;CODE&gt;pauseReason&lt;/CODE&gt;&lt;BR /&gt;
    | stats count by SerialNumber,pause_reason &lt;BR /&gt;
    | eventstats sum(count) as total by SerialNumber&lt;BR /&gt;
    | sort - total&lt;BR /&gt;
    | streamstats dc(SerialNumber) as i&lt;BR /&gt;
    | where i&amp;lt;=5&lt;BR /&gt;
    | chart values(count) over SerialNumber by pause_reason&lt;/P&gt;

&lt;P&gt;thanks for your help&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406144#M170882</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-09-30T00:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406145#M170883</link>
      <description>&lt;P&gt;Awesome glad to hear it's working ! You can convert your comment to an answer and accept it so other can use if ever they have the same issue ^^ Also give @woodcock 's answer a try, it should do the trick and looks way easier.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 06:45:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406145#M170883</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-17T06:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: show top 5 values in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406146#M170884</link>
      <description>&lt;P&gt;thanks&lt;BR /&gt;
i finally did it that way :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index=ssys_*_fdm OR index=other_fdm) pauseReason: NOT "pauseReason: NotPaused" pauseReason: NOT "pauseReason: UserPaused" 
| pauseReason
| stats count by SerialNumber,pause_reason 
| eventstats sum(count) as total by SerialNumber
| sort - total
| streamstats dc(SerialNumber) as i
| where i&amp;lt;=5
| chart values(count) over SerialNumber by pause_reason
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 17 Jun 2019 06:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-top-5-values-in-column-chart/m-p/406146#M170884</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-17T06:57:55Z</dc:date>
    </item>
  </channel>
</rss>

