Getting Data In

Sub Query ? on Syslog results

ids
New Member

I have some data (cleaned syslog) that we are using the Top function to see top Destination IP addresses in some log data

From the results shown, how can you get it to display data from normal additional queries that I run on this data like | top Src_Address or | top Dst_Port..... wether displayed via a link or inline ...

I am guessing its a subquery but cant see how you define this

thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

Splunk has a top command to do this:

... | top Src_Address
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...