Splunk Search
Highlighted

How to find top content by some other field and also show content name?

New Member

I have data in index "main" and sourcetype "app" and fields "content_name" and "os".
So how can I create Top content by OS?

0 Karma
Highlighted

Re: How to find top content by some other field and also show content name?

Esteemed Legend

Like this:

index=main sourcetype=app | top content BY os

View solution in original post

0 Karma