I have below fields on so i would like group top occurring events
like sort by severity critical and display message
top messages with IP etc.
Any help would be much appreciated .
I am not sure I understand your message but perhaps you are looking for the contingency command which you use like this:
... | contingency issueSeverity IP