Splunk Search

How to show table with highest values in a column

maniu1609
Path Finder

Timechart output shows me table with two columns. column one is _time and column two is interger values.
example:
_time count
2018-05-22 10:07:16 4
2018-05-22 10:08:09 4
2018-05-22 10:07:45 4
2018-05-22 10:06:54 2
2018-05-22 10:07:11 1

Now I want display table with highest count column. Since 4 is the highest value in column "count", I want to display those rows having highest count 4 as below :

_time count
2018-05-22 10:07:16 4
2018-05-22 10:08:09 4
2018-05-22 10:07:45 4

How I can achieve this. Thanks in advance!!

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Try like this

your current search giving field _time and count 
| eventstats max(count) as max
| where count=max | fields - max

View solution in original post

somesoni2
Revered Legend

Try like this

your current search giving field _time and count 
| eventstats max(count) as max
| where count=max | fields - max

maniu1609
Path Finder

Great!!. Thanks a lot!!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...