Splunk Search

Grouping top occurring events.

kbharatunix
New Member

I have below fields on so i would like group top occurring events

like sort by severity critical and display message

top messages with IP etc.

customerID 15
dateUpdated 29
initialResolution 1
issueSeverity 331
sourcetype 2
status 2
summary 36
supportType 2
ticketID 37
accountName 11
csrName
customerEmail 15
dateClosed

Any help would be much appreciated .

Tags (3)
0 Karma

woodcock
Esteemed Legend

I am not sure I understand your message but perhaps you are looking for the contingency command which you use like this:

... | contingency issueSeverity IP
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...