Splunk Search

How to add another field using top limit command?

grotti
Engager

Hello! I need some help from splunkers!!!

 

I'm using the search index=notable | search status_label=Closed | top limit=5 rule_title in the Splunk Enterprise Security, to list top 10 rule_title values.

 

But i need to bring the field "comment" of each rule_title in the table.

 

Can please help me?

 

Tks!!!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @grotti,

if you haven't too many comments for each row, you could use:

index=notable status_label=Closed 
| stats values(comment) AS comment BY rule_title
| sort 10 -count

Ciao.

Giuseppe

0 Karma

bowesmana
SplunkTrust
SplunkTrust

If the comment field is always the same for the rule, then just add the comment to the top command

index=notable 
| search status_label=Closed 
| top limit=5 rule_title comment
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...