The task guide for the Forage job sim states this:
For example, to add “Count by category” to your dashboard, type out
sourcetype="fraud_detection.csv" | top category in the search field. This action counts
the number in each category
Yet I am guessing Splunk has been updated since the task guide was created because the search doesn't register the command. I have tried others but, am not receiving the desired results.
Does anyone know about this? or a different command to give me a valid bar chart in visualization?
Hello @MatthewWolf,
If you need the number of event counts for a particular category, you can use the following search:
index=<<index_name>> sourcetype="fraud_detection.csv"
| stats count by category
| sort - count
This will give you output of all the categories present with event count in decreasing order (i.e. highest count first).
Thanks,
Tejas.
---
If the above solution helps, an upvote is appreciated.!!