Getting Data In

Get top 20 countries from Cisco ASA events

New Member

Hi,

I am searching my Cisco ASA logs to count where an IP originates from by country.

It looks like this:

eventtype= | iplocation src_ip | stats count by Country

It works well to give me a count of all the countries, but I can't get it to give me the top 20 only. I have tried multiple combinations of the 'top' and 'head'

I don't want to just choose 20 results per page as I need to generate reports for this.

Can anyone help me out?

0 Karma
1 Solution

SplunkTrust
SplunkTrust

Try

eventtype= | iplocation src_ip | stats count by Country|sort 20 - count

View solution in original post

SplunkTrust
SplunkTrust

Try

eventtype= | iplocation src_ip | stats count by Country|sort 20 - count

View solution in original post

New Member

This worked, thanks

0 Karma

SplunkTrust
SplunkTrust

You can try this instead:

eventtype= | iplocation src_ip | top limit=20 Country
0 Karma