Splunk Search

How to edit my search to get the count for the Top 5 and Others?

fmpa_isaac
Path Finder

Can anyone help me get the count for Top 5 plus an Others count for the following please? Thank you

sourcetype="cisco:asa" action=blocked | stats count by src_ip, dest_ip, dest_port  | sort - by count | rename src_ip as Src, dest_ip as Dest, dest_port as Port | addcoltotals
0 Karma
1 Solution

javiergn
Super Champion

Try this:

sourcetype="cisco:asa" action=blocked 
| top 5 src_ip, dest_ip, dest_port  useother=t
| rename src_ip as Src, dest_ip as Dest, dest_port as Port
| addcoltotals

View solution in original post

0 Karma

javiergn
Super Champion

Try this:

sourcetype="cisco:asa" action=blocked 
| top 5 src_ip, dest_ip, dest_port  useother=t
| rename src_ip as Src, dest_ip as Dest, dest_port as Port
| addcoltotals
0 Karma

fmpa_isaac
Path Finder

Awesome, Thank you

0 Karma

fmpa_isaac
Path Finder

Also, I want to keep a totals row at the bottom. So the top 5, then an others row plus a Totals row.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...