Archive
Highlighted

countfield question

Communicator

What is the role of countfield please? What is it doing here?
index="accesslog" source="access.log" host="AccessLog" status=500
| top action countfield="HTTP
DESCRIPTION"

Tags (1)
0 Karma
Highlighted

Re: countfield question

Champion

Hi

For each value returned by the top command, the results also return a count of the events that have that value. This argument specifies the name of the field that contains the count. The count is returned by default. If you do not want to return the count of events, specify showcount=false.

For more info you can check splunk doc:

https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Top

View solution in original post