Trying to get a nice list of the top 10 countries a firewall is blocking. If I run the search in the search app, it comes back with the columns of Country and count. I use Dashboard Studio and I use the same search as a data source and I get Country, count, and _tc. I am guessing I am missing a flag to not show the total count.
Splunk Search:
(index=netfw OR index=netproxy) (sourcetype="pan:threat" OR sourcetype="pan:traffic") action="dropped" (src_ip!=10.0.0.0/8 AND src_ip!=172.16.0.0/12 AND src_ip!=192.168.0.0/16) | iplocation src_ip | top limit=10 Country showperc=false
| fields Country,count
Studio Visualization:
{
"type": "splunk.table",
"options": {
"showRowNumbers": true
},
"dataSources": {
"primary": "ds_69PTFLxT"
},
"title": "Top 10 Blocked Countries",
"showProgressBar": true,
"context": {},
"showLastUpdated": false
}
You can use | fields - _tc
or you can use |table field1 field2 ... (just without _tc)