Splunk Search

How to filter top 3 counts over each group?

amylala
Explorer

Here is data I get after count by Message and Error Code.

Message ErrorCode Count
Msg1 1000 500
Msg1 1001 400
Msg1 1002 300
Msg1 1003 200
Msg1 1004 100
Msg2 2000 550
Msg2 2001 450
Msg2 2002 350
Msg2 2003 250
Msg2 2004 150

I want top 3 count of each Msg. How can I get result as below?
Message ErrorCode Count
Msg1 1000 500
Msg1 1001 400
Msg1 1002 300
Msg2 2000 550
Msg2 2001 450
Msg2 2002 350

Tags (3)
0 Karma
1 Solution

pradeepkumarg
Influencer

... | sort Message -count | dedup 3 Message

View solution in original post

pradeepkumarg
Influencer

... | sort Message -count | dedup 3 Message

amylala
Explorer

Thanks, gpradeepkumarreddy.
This method is more simple. But It is sort by count after dedup.
I need to sort again at the end.

0 Karma

amylala
Explorer

Sorry, my mistake, no need to sorting is not changed after dedup

0 Karma

somesoni2
Revered Legend

Try something like this

Your current search giving Count by Message and ErrorCode | sort 0 Message -Count | streamstats count as rank by Message | where rank<=3 | fields - rank 

amylala
Explorer

Thanks, somesoni2.
This is really what I want. 🙂

0 Karma

jeffland
SplunkTrust
SplunkTrust

Does this do the trick?

... | top limit=3 showperc=f ErrorCode by Message

Do it instead of stats count by Message ErrorCode.

amylala
Explorer

Thanks, jeffland. It works! 🙂

Do you have any idea if I want to search with data model? (|tstats command)
Seem I can only use raw search now.

0 Karma

jeffland
SplunkTrust
SplunkTrust

Sorry, I don't know why you wouldn't be able to use this with a data model. I must admit though that I don't work with data models a lot.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...