Splunk Search

How to find top content by some other field and also show content name?

tariqazeem123
New Member

I have data in index "main" and sourcetype "app" and fields "content_name" and "os".
So how can I create Top content by OS?

0 Karma
1 Solution

woodcock
Esteemed Legend

Like this:

index=main sourcetype=app | top content BY os

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

index=main sourcetype=app | top content BY os
0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...