Are you looking for this?
source="F:Splunk_Log Files*" status ="Allow" src_ip | stats sum(recv_bytes) as sum_recv_bytes by src_ip | sort - sum_recv_bytes | head 10
source="F:Splunk_Log Files*" status ="Allow" src_ip | stats sum(recv_bytes) as Bytes by src_ip | top limit=10 Bytes
Are you looking for this?
source="F:Splunk_Log Files*" status ="Allow" src_ip | stats sum(recv_bytes) as sum_recv_bytes by src_ip | sort - sum_recv_bytes | head 10