Splunk Search

Grouping top occurring events.

kbharatunix
New Member

I have below fields on so i would like group top occurring events

like sort by severity critical and display message

top messages with IP etc.

customerID 15
dateUpdated 29
initialResolution 1
issueSeverity 331
sourcetype 2
status 2
summary 36
supportType 2
ticketID 37
accountName 11
csrName
customerEmail 15
dateClosed

Any help would be much appreciated .

Tags (3)
0 Karma

woodcock
Esteemed Legend

I am not sure I understand your message but perhaps you are looking for the contingency command which you use like this:

... | contingency issueSeverity IP
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...