Splunk Search

How to display current and previous ranks of top 10 error messages with the respective count and percentage contribution on daily basis.

abhi_syntel_hum
New Member

Hi,

Initially I tried with:

ConsumerService HostEnvironmentName=PROD| top limit=10 message

to get the daily details, then to display current rank modified with:

ConsumerService HostEnvironmentName=PROD| top limit=10 message | streamstats count as C.Rank

but I am struggling to get the ranks of top 10 messages for previous day,

Please guide me to right direction.

Abhishek

0 Karma
1 Solution

sundareshr
Legend

See if this gives you what you're looking for

index=_internal sourcetype=*web* earliest=-1d@d | top 100 uri | streamstats count as "Yesterday's Rank" | where [ search index=_internal sourcetype=*web* earliest=@d | top 10 uri | table uri] | rename percent as "Yesterday's Percent" | appendcols [ search index=_internal sourcetype=*web* earliest=@d | top 10 uri ] | streamstats count as "Today's Rank" | rename percent as "Today's Percent" | fields - count

View solution in original post

0 Karma

sundareshr
Legend

See if this gives you what you're looking for

index=_internal sourcetype=*web* earliest=-1d@d | top 100 uri | streamstats count as "Yesterday's Rank" | where [ search index=_internal sourcetype=*web* earliest=@d | top 10 uri | table uri] | rename percent as "Yesterday's Percent" | appendcols [ search index=_internal sourcetype=*web* earliest=@d | top 10 uri ] | streamstats count as "Today's Rank" | rename percent as "Today's Percent" | fields - count
0 Karma

abhi_syntel_hum
New Member

Thanks sundareshr for quick response.
The solution is perfect. I needed error counts also, so I replaced fields - count -> rename count as Count
Thanks again !!

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...