Splunk Search

Display top 3 Employees by Class Frequency

efelder0
Communicator

I have 2 fields in CSV that I want to only display the top 3 employees by the Class frequency. I know the Top command will suffice, but not sure of the syntax.

Here is a sampling of data:
Employee_ID Class_Frequency
tsmith 2388
mjones 81
smurphy 6591
tpayne 1309
jjones 109

Tags (2)
0 Karma

jfreund
Explorer

| top limit=3 Class_Frequency by Employee_ID showcount=f showperc=f

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee
 * | chart count(Employee_ID) as count by Class_Frequency | sort - count | head 3

or


 * | stats count(Employee_ID) by Class_Frequency | sort - count | head 3

efelder0
Communicator

sort - Classification_Frequency | head 3 worked..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...