Splunk Search

Forage Task Guide

MatthewWolf
New Member

The task guide for the Forage job sim states this: 

For example, to add “Count by category” to your dashboard, type out
sourcetype="fraud_detection.csv" | top category in the search field. This action counts
the number in each category

Yet I am guessing Splunk has been updated since the task guide was created because the search doesn't register the command. I have tried others but, am not receiving the desired results.

Does anyone know about this? or a different command to give me a valid bar chart in visualization?

0 Karma

tej57
Builder

Hello @MatthewWolf,

If you need the number of event counts for a particular category, you can use the following search:

 

index=<<index_name>> sourcetype="fraud_detection.csv" 
| stats count by category
| sort - count

This will give you output of all the categories present with event count in decreasing order (i.e. highest count first).

 

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.!!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...