Splunk Search

How to display message related to particular fields?

manohart31
New Member

page="MIR" postid="2824567904373133_10151428930538134" message="Foot stools from MI..." time="2013-01-21" likes="188" comments="9" fromid="282904373133" picCount="1" videocount="0" linlcount="0" shares="0"

tried this query: sourcetype="..." |stats max(likes) as likes by page| table page,likes, message

My intention is to display a message with max likes but the above query does not work

Tags (2)
0 Karma

ranjyotiprakash
Communicator

Use the following command to get a list which contains pages and max likes as columns :

.... | chart max(likes) AS Likes by page

Have a look at following Splunk Documentation :
link text

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...