I have below fields on so i would like group top occurring events
like sort by severity critical and display message
top messages with IP etc.
customerID 15
dateUpdated 29
initialResolution 1
issueSeverity 331
sourcetype 2
status 2
summary 36
supportType 2
ticketID 37
accountName 11
csrName
customerEmail 15
dateClosed
Any help would be much appreciated .
I am not sure I understand your message but perhaps you are looking for the contingency
command which you use like this:
... | contingency issueSeverity IP