Splunk Search

Display top 3 Employees by Class Frequency

efelder0
Communicator

I have 2 fields in CSV that I want to only display the top 3 employees by the Class frequency. I know the Top command will suffice, but not sure of the syntax.

Here is a sampling of data:
Employee_ID Class_Frequency
tsmith 2388
mjones 81
smurphy 6591
tpayne 1309
jjones 109

Tags (2)
0 Karma

jfreund
Explorer

| top limit=3 Class_Frequency by Employee_ID showcount=f showperc=f

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee
 * | chart count(Employee_ID) as count by Class_Frequency | sort - count | head 3

or


 * | stats count(Employee_ID) by Class_Frequency | sort - count | head 3

efelder0
Communicator

sort - Classification_Frequency | head 3 worked..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...