Splunk Search

How to add another field using top limit command?

grotti
Engager

Hello! I need some help from splunkers!!!

 

I'm using the search index=notable | search status_label=Closed | top limit=5 rule_title in the Splunk Enterprise Security, to list top 10 rule_title values.

 

But i need to bring the field "comment" of each rule_title in the table.

 

Can please help me?

 

Tks!!!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @grotti,

if you haven't too many comments for each row, you could use:

index=notable status_label=Closed 
| stats values(comment) AS comment BY rule_title
| sort 10 -count

Ciao.

Giuseppe

0 Karma

bowesmana
SplunkTrust
SplunkTrust

If the comment field is always the same for the rule, then just add the comment to the top command

index=notable 
| search status_label=Closed 
| top limit=5 rule_title comment
0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...