All Apps and Add-ons

How to increase search index destination ip addresses results based from default values of 10 to more

syedfahad
New Member

Dears

By default I am getting 10 values under destination ip addresses. Please find image as attached and let me know how can I get more IP addresses with hit count and Percentage usage.

alt text

Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

You should add "| top limit=50 dest_ip" at the end of your query.

r. Ismo

View solution in original post

0 Karma

wmyersas
Builder

When you click the field in the events view, you only ever get the top 10 entries - it's a summary statistic 🙂

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You should add "| top limit=50 dest_ip" at the end of your query.

r. Ismo

0 Karma

syedfahad
New Member

Thank you for the help.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...