I am attempting to get a listing of the max top 10 by a field.
I am able to get the the top 10 by doing this:
[search goes here] | top limit=10 message.facets.duration
I can get the max by doing:
[search goes here] | stats max(message.facets.duration)
I am trying to figure out how to get the max top 10.
How about this
[search goes here] | sort 10 -message.facets.duration
Yea that did the trick. I over thought by quite a bit. Thanks
top
gives you the top occurrences of a field value. So if your duration field had "1" as a value more times than values of "100000", "1" would be the top entry. Probably not what you wanted! 🙂