<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: countfield question in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/countfield-question/m-p/470008#M192091</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;For each value returned by the top command, the results also return a count of the events that have that value. This argument specifies the name of the field that contains the count. The count is returned by default. If you do not want to return the count of events, specify showcount=false.&lt;/P&gt;

&lt;P&gt;For more info you can check splunk doc:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Top"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Top&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Dec 2019 10:09:01 GMT</pubDate>
    <dc:creator>vnravikumar</dc:creator>
    <dc:date>2019-12-27T10:09:01Z</dc:date>
    <item>
      <title>countfield question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/countfield-question/m-p/470007#M192090</link>
      <description>&lt;P&gt;What is the role of countfield please? What is it doing here?&lt;BR /&gt;
index="access_log" source="access.log" host="AccessLog" status=500&lt;BR /&gt;
| top action countfield="HTTP_DESCRIPTION"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/countfield-question/m-p/470007#M192090</guid>
      <dc:creator>palisetty</dc:creator>
      <dc:date>2020-09-30T03:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: countfield question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/countfield-question/m-p/470008#M192091</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;For each value returned by the top command, the results also return a count of the events that have that value. This argument specifies the name of the field that contains the count. The count is returned by default. If you do not want to return the count of events, specify showcount=false.&lt;/P&gt;

&lt;P&gt;For more info you can check splunk doc:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Top"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Top&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 10:09:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/countfield-question/m-p/470008#M192091</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-27T10:09:01Z</dc:date>
    </item>
  </channel>
</rss>

