Splunk Search

Forage Task Guide

MatthewWolf
New Member

The task guide for the Forage job sim states this: 

For example, to add “Count by category” to your dashboard, type out
sourcetype="fraud_detection.csv" | top category in the search field. This action counts
the number in each category

Yet I am guessing Splunk has been updated since the task guide was created because the search doesn't register the command. I have tried others but, am not receiving the desired results.

Does anyone know about this? or a different command to give me a valid bar chart in visualization?

0 Karma

tej57
Builder

Hello @MatthewWolf,

If you need the number of event counts for a particular category, you can use the following search:

 

index=<<index_name>> sourcetype="fraud_detection.csv" 
| stats count by category
| sort - count

This will give you output of all the categories present with event count in decreasing order (i.e. highest count first).

 

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.!!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...